[Research] CVE-2025-10263 (ARM Erratum 4193794) & Potential Kernel Escalation on Switch 2

starbucks-c

New Member
Newbie
Joined
Aug 30, 2026
Messages
1
Reaction score
8
Trophies
0
Age
26
XP
13
Country
United States
The Nintendo Switch 2 relies on the Nvidia Tegra T239 SoC, which uses ARM Cortex-A78C cores.

Because CVE-2025-10263 (ARM Erratum 4193794) is an erratum baked directly into the physical Cortex-A78C silicon, the CPU cores contain the microarchitectural flaw at launch, which can cause issues in the TPLI, hence causing a privilage escalation leading to a potential kernel-exploit (E0->E1)

A physical microarchitectural defect in the Cortex-A78C Load/Store Unit (LSU) and interconnect. During multi-core memory operations, a Data Synchronization Barrier (⁠DSB IS⁠) completes prematurely before a secondary core flushes pending writes from its internal Store Buffer following a broadcast Translation Lookaside Buffer Invalidate (⁠TLBI IS⁠).

Starting from an underprivileged entry point such as the Userland Base, especially when bypassed the ARM-PAC like Gezine demonstrated on X, there is a high probability of CVE-2025-10263 affecting the Nintendo Switch 2 triggering a race condition via an ROP-Chain possibility leading to a kernel exploit on the Nintendo Switch 2 (Tegra T239).

Affected Nintendo Switch 2 Firmwares: Every firmware supporting Switch 1/2 backwards compatibility released before June 2026.

Sources:

https://www.openwall.com/lists/oss-security/2026/06/09/13

https://access.redhat.com/security/...extIdCarryOver=true&sc_cid=RHCTG0180000382538

https://support.arm.com/documentation/SDEN-2004089/14-0?lang=en&rev=14.0

https://support.arm.com/documentation/112137/1-0/
 

Attachments

  • IMG_6955.png
    IMG_6955.png
    642.2 KB · Views: 2
It would be awesome to see this in action if it does happen to lead to a kernel exploit without any external hardware. Considering that I've seen a lot of naysayers deny and mock the use of staying low, I feel like a turning point is not far. :wink:
 
  • Haha
Reactions: ChibiMofo
The Nintendo Switch 2 relies on the Nvidia Tegra T239 SoC, which uses ARM Cortex-A78C cores.

Because CVE-2025-10263 (ARM Erratum 4193794) is an erratum baked directly into the physical Cortex-A78C silicon, the CPU cores contain the microarchitectural flaw at launch, which can cause issues in the TPLI, hence causing a privilage escalation leading to a potential kernel-exploit (E0->E1)

[blah, blah, blah]
I think all of us know how to use ChatGPT or Google's AI mode by now. No need to post junk content like this here.
Post automatically merged:

Considering that I've seen a lot of naysayers deny and mock the use of staying low, I feel like a turning point is not far. :wink:
Oh, hi there @lightwo! Yeah, I'm still here. 😎

And the Switch 2 is still unhackable. 🥰
 
  • Like
Reactions: [Truth]
I think all of us know how to use ChatGPT or Google's AI mode by now. No need to post junk content like this here.
Post automatically merged:


Oh, hi there @lightwo! Yeah, I'm still here. 😎

And the Switch 2 is still unhackable. 🥰
Unlike before, there were sources attached, otherwise I wouldn't have bothered to comment.
 
Affected Nintendo Switch 2 Firmwares: Every firmware supporting Switch 1/2 backwards compatibility released before June 2026.
For those of you who don't have an unopened Switch 2, don't suddenly be afraid to update it or hold your breath until you turn blue. There is no evidence that any Switch 2 firmware has any problems. Whether the TLBI sequences they use were ever vulnerable in the first place is still in doubt. And even if they were, there is no known way to exploit it—the TLBI instructions and the relevant sequences are privileged.

We all want CFW on Switch 2 but there is no reason to not enjoy your toy now.
 
Last edited by TomSwitch,
  • Like
Reactions: lightwo
For those of you who don't have an unopened Switch 2, don't suddenly be afraid to update it or hold your breath until you turn blue. There is no evidence that any Switch 2 firmware has any problems. Whether the TLBI sequences they use were ever vulnerable in the first place is still in doubt. And even if they were, there is no known way to exploit it—the TLBI instructions and the relevant sequences are privileged.

We all want CFW on Switch 2 but there is no reason to not enjoy your toy now.
Yeah see the only problem with that is I haven't found any decent games to play on the Switch 2 so mine remains on launch firmware (+ SD Express).
 
Yeah see the only problem with that is I haven't found any decent games to play on the Switch 2 so mine remains on launch firmware (+ SD Express).
You can use it as a Switch pro. Faster load time, nicer screen, lower chance of slowdown.
 

Site & Scene News

Popular threads in this forum