The Nintendo Switch 2 relies on the Nvidia Tegra T239 SoC, which uses ARM Cortex-A78C cores.
Because CVE-2025-10263 (ARM Erratum 4193794) is an erratum baked directly into the physical Cortex-A78C silicon, the CPU cores contain the microarchitectural flaw at launch, which can cause issues in the TPLI, hence causing a privilage escalation leading to a potential kernel-exploit (E0->E1)
A physical microarchitectural defect in the Cortex-A78C Load/Store Unit (LSU) and interconnect. During multi-core memory operations, a Data Synchronization Barrier (DSB IS) completes prematurely before a secondary core flushes pending writes from its internal Store Buffer following a broadcast Translation Lookaside Buffer Invalidate (TLBI IS).
Starting from an underprivileged entry point such as the Userland Base, especially when bypassed the ARM-PAC like Gezine demonstrated on X, there is a high probability of CVE-2025-10263 affecting the Nintendo Switch 2 triggering a race condition via an ROP-Chain possibility leading to a kernel exploit on the Nintendo Switch 2 (Tegra T239).
Affected Nintendo Switch 2 Firmwares: Every firmware supporting Switch 1/2 backwards compatibility released before June 2026.
Sources:
https://www.openwall.com/lists/oss-security/2026/06/09/13
https://access.redhat.com/security/...extIdCarryOver=true&sc_cid=RHCTG0180000382538
https://support.arm.com/documentation/SDEN-2004089/14-0?lang=en&rev=14.0
https://support.arm.com/documentation/112137/1-0/
Because CVE-2025-10263 (ARM Erratum 4193794) is an erratum baked directly into the physical Cortex-A78C silicon, the CPU cores contain the microarchitectural flaw at launch, which can cause issues in the TPLI, hence causing a privilage escalation leading to a potential kernel-exploit (E0->E1)
A physical microarchitectural defect in the Cortex-A78C Load/Store Unit (LSU) and interconnect. During multi-core memory operations, a Data Synchronization Barrier (DSB IS) completes prematurely before a secondary core flushes pending writes from its internal Store Buffer following a broadcast Translation Lookaside Buffer Invalidate (TLBI IS).
Starting from an underprivileged entry point such as the Userland Base, especially when bypassed the ARM-PAC like Gezine demonstrated on X, there is a high probability of CVE-2025-10263 affecting the Nintendo Switch 2 triggering a race condition via an ROP-Chain possibility leading to a kernel exploit on the Nintendo Switch 2 (Tegra T239).
Affected Nintendo Switch 2 Firmwares: Every firmware supporting Switch 1/2 backwards compatibility released before June 2026.
Sources:
https://www.openwall.com/lists/oss-security/2026/06/09/13
https://access.redhat.com/security/...extIdCarryOver=true&sc_cid=RHCTG0180000382538
https://support.arm.com/documentation/SDEN-2004089/14-0?lang=en&rev=14.0
https://support.arm.com/documentation/112137/1-0/








