The Nintendo Switch 2 relies on the Nvidia Tegra T239 SoC, which uses ARM Cortex-A78C cores.
Because CVE-2025-10263 (ARM Erratum 4193794) is an erratum baked directly into the physical Cortex-A78C silicon due to a flaw in the RTL, the CPU cores most likely contain the microarchitectural flaw at launch, which can cause issues in the translation lookaside buffer (TLB), hence causing a privilage escalation leading to a potential kernel-exploit (EL0->EL1), so basically a flaw in the RTL logic in the LSU&interconnect causing a race condition which also might lead to a privilege escalation in the execution layers of the ARM-Architecture, which the nintendo switch 2 corresponds by. As this vulnerability was discovered around november 2025& got fixed in June 2026 so after the release of the nintendo switch 2, the vulnerability should be there at least in the current revision.
During multi-core memory operations, a Data Synchronization Barrier (DSB IS) completes prematurely before a secondary core flushes pending writes from its internal Store Buffer following a broadcast Translation Lookaside Buffer Invalidate (TLBI IS).
Starting from an underprivileged entry point such as the Userland Base, especially when bypassed the ARM-PAC like Gezine demonstrated on X, there is a high probability of CVE-2025-10263 affecting the Nintendo Switch 2.
Affected Nintendo Switch 2 Firmwares: Every firmware supporting Switch 1/2 backwards compatibility released before June 2026 (up to firmware 22.1.0)
Sources:
https://www.openwall.com/lists/oss-security/2026/06/09/13
https://access.redhat.com/security/cve/cve-2025-10263?extIdCarryOver=true&sc_cid=RHCTG0180000382538?extIdCarryOver=true&sc_cid=RHCTG0180000382538
https://support.arm.com/documentation/SDEN-2004089/14-0?lang=en&rev=14.0
https://support.arm.com/documentation/112137/1-0/
Gezine’s Userland Exploit:
Because CVE-2025-10263 (ARM Erratum 4193794) is an erratum baked directly into the physical Cortex-A78C silicon due to a flaw in the RTL, the CPU cores most likely contain the microarchitectural flaw at launch, which can cause issues in the translation lookaside buffer (TLB), hence causing a privilage escalation leading to a potential kernel-exploit (EL0->EL1), so basically a flaw in the RTL logic in the LSU&interconnect causing a race condition which also might lead to a privilege escalation in the execution layers of the ARM-Architecture, which the nintendo switch 2 corresponds by. As this vulnerability was discovered around november 2025& got fixed in June 2026 so after the release of the nintendo switch 2, the vulnerability should be there at least in the current revision.
During multi-core memory operations, a Data Synchronization Barrier (DSB IS) completes prematurely before a secondary core flushes pending writes from its internal Store Buffer following a broadcast Translation Lookaside Buffer Invalidate (TLBI IS).
Starting from an underprivileged entry point such as the Userland Base, especially when bypassed the ARM-PAC like Gezine demonstrated on X, there is a high probability of CVE-2025-10263 affecting the Nintendo Switch 2.
Affected Nintendo Switch 2 Firmwares: Every firmware supporting Switch 1/2 backwards compatibility released before June 2026 (up to firmware 22.1.0)
Sources:
https://www.openwall.com/lists/oss-security/2026/06/09/13
https://access.redhat.com/security/cve/cve-2025-10263?extIdCarryOver=true&sc_cid=RHCTG0180000382538?extIdCarryOver=true&sc_cid=RHCTG0180000382538
https://support.arm.com/documentation/SDEN-2004089/14-0?lang=en&rev=14.0
https://support.arm.com/documentation/112137/1-0/
Gezine’s Userland Exploit:
Attachments
Last edited by starbucks-c,












