Switch TrustZoneHax on 4.x

nintendo-switch-15-1-630x354.jpg

The ReSwitched Hacking Team have done it again. motezazer, ktemkin and SciresM have achieved code execution on 4.1.0, the latest version at the time of writing this, via deja vu at TrustZone level. This means devices on 4.1.0 and below will be able to gain access to the whole system. SciresM strongly advises to not update in the future.

After less than a year, the Switch hacking team has moved extremely fast and now have got full access on the latest version. The progress being made is incredible, and in comparison, the 3DS took around 2 years to get ARM9 access. The scene is looking very promising so far and we are very lucky to have such talented people working on the Switch.

:arrow: Source
 
Last edited by Deleted member 381889,

8BitWonder

Small Homebrew Dev
Member
Joined
Jan 23, 2016
Messages
2,489
Trophies
1
Location
47 4F 54 20 45 45 4D
XP
5,340
Country
United States
So me having a Switch on 8.0.0 means im still fucked right? My switch is on partially patched (XAW1011) and it automatically updated to 8.0.0 without my knowing (That or my gf did it by accident)

Will this work on my unit?
Assuming you can't push payloads on your switch in RCM, then yes unfortunately you're boned if you wanted to run CFW. 8.0.0 patched the last known TZ vulnerability.

Unless a new vulnerability is found (could be a long time/never) the highest fw an ipatched unit will be able to run CFW is going to be 7.0.1.
 

hippy dave

BBMB
Member
Joined
Apr 30, 2012
Messages
9,856
Trophies
2
XP
28,853
Country
United Kingdom
So me having a Switch on 8.0.0 means im still fucked right? My switch is on partially patched (XAW1011) and it automatically updated to 8.0.0 without my knowing (That or my gf did it by accident)

Will this work on my unit?
Partially patched isn't a thing, I guess your serial is in the range where some are patched and some aren't, so you need to find out if yours is or not by putting it in RCM mode and sending a payload.
 

Nononoki

Well-Known Member
Newcomer
Joined
Jan 31, 2012
Messages
84
Trophies
0
XP
484
Country
Gambia, The
Currently on 8.0 but my original fuses from 4.0.X are not burned, but lost my backup 4.0.X (6.2 is my earliest backup available). Anyway to downgrade without burning fuses and without backup? Just install old Firmware file with Choidujour? Never done that before, I just wanna know if there are major risks in downgrading. Or wait for 6.2+ support for warmboot?
 
Last edited by Nononoki,

pLaYeR^^

Doctor Switch
Member
Joined
Sep 18, 2014
Messages
3,151
Trophies
1
Age
27
Location
Austria
XP
3,874
Country
Austria
Currently on 8.0 but my original fuses from 4.0.X are not burned, but lost my backup 4.0.X (6.2 is my earliest backup available). Anyway to downgrade without burning fuses and without backup? Or wait for 6.2+ support for warmboot?
Rebuild NAND for 4.0.X? If you don't need clean 4.0.X NAND you can also simply downgrade with ChoiDujourNX to 4.0.X.
 
Last edited by pLaYeR^^,

Nononoki

Well-Known Member
Newcomer
Joined
Jan 31, 2012
Messages
84
Trophies
0
XP
484
Country
Gambia, The
Rebuild NAND for 4.0.X? If you don't need clean 4.0.X NAND you can also simply downgrade with ChoiDujourNX to 4.0.X.

Ah thanks - any reports that downgrading with ChoidujourNX bricks consoles? Or is it (mostly) safe since I have backups? Never had a clean NAND so I don't care ;)
 

ZachyCatGames

Well-Known Member
Member
Joined
Jun 19, 2018
Messages
3,398
Trophies
1
Location
Hell
XP
4,208
Country
United States
Ah thanks - any reports that downgrading with ChoidujourNX bricks consoles? Or is it (mostly) safe since I have backups? Never had a clean NAND so I don't care ;)
if you don’t use the factory reset option in ChoiNX when downgrading you’ll likely get a fatal when you start the system
 

Rimaahkehs

Member
Newcomer
Joined
May 21, 2019
Messages
11
Trophies
0
Age
28
XP
55
Country
India
I am very new to the seen and in desperate need of help please help me by telling me where to look for these exploits I (mean link) to hack my ipatched unit I am from India and unable to find help anywhere else please

--------------------- MERGED ---------------------------

I am on 4.1 firmware
 

hippy dave

BBMB
Member
Joined
Apr 30, 2012
Messages
9,856
Trophies
2
XP
28,853
Country
United Kingdom
I am very new to the seen and in desperate need of help please help me by telling me where to look for these exploits I (mean link) to hack my ipatched unit I am from India and unable to find help anywhere else please

--------------------- MERGED ---------------------------

I am on 4.1 firmware
Just keep waiting a bit longer, they will be posted on this forum when they're ready.
 

Sticker

Well-Known Member
Newcomer
Joined
Oct 1, 2018
Messages
89
Trophies
0
Age
34
XP
683
Country
Vietnam
I remember someone said we can boot any CFW without care about furse count because ignoring count feature of hakate or something similar. So can we downgrade to 4.0 and take advanced of Trust Zone vulnerability without care about burning furses?
 

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,005
Trophies
2
Age
29
Location
New York City
XP
13,369
Country
United States
I remember someone said we can boot any CFW without care about furse count because ignoring count feature of hakate or something similar. So can we downgrade to 4.0 and take advanced of Trust Zone vulnerability without care about burning furses?
If you can boot the console via Hekate and subsequently CFW, what would be the point of booting Deja Vu?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: Ohkay