Homebrew Nintendo switch 2 modding ideas

Status
Not open for further replies.

Flipped_Out999

New Member
Newbie
Joined
Oct 5, 2026
Messages
2
Reaction score
1
Trophies
0
Age
36
XP
3
Country
Bulgaria
So they say the NS2 (Switch 2) is unhackable. Well, it's close. The attempts that were tried did reach userland code execution, but stopped one privilege ring short of the kernel.

So I came up with an idea of how to mod it (DISCLAIMER: put my idea in practice only if you give me credit for bringing it up. Also, I didn't check if anyone else thought the same as me — ideas like this converge fast, so verify before building). So the principle is simple: you build a spoofing device that impersonates a Joy-Con 2 over BLE, which sends a crafted HID report sequence when triggered by a click pattern. That sequence is meant to hit a memory-safety bug in the console-side input parser, which then loads unsigned homebrew from the microSD Express card (the slot exposes a real NVMe/PCIe link, so storage access is possible — execution is the hard part). Please point out the mistakes I made with my idea.

EDIT: the payload should be coded (cuz no firmware like that exists) and run on an external nRF52840 board flashing XD2Joy-style firmware to mimic a real Joy-Con 2, rather than burning anything into the official controller — its image is signature-verified and can only be updated through System Settings → Controllers & Accessories, so reprogramming it would first require defeating Nintendo's secure boot, which nobody has done. Also make sure the device stays fully functional as a normal controller until you activate the trigger, so the console sees nothing unusual.

SECOND EDIT (honest scope): this is not a jailbreak by itself. Everything above is step 4 of the chain. Steps 1–3 are unsolved and unpublished: (1) a memory-safety bug reachable from controller input reports in the HID/BT stack, (2) a PAC-aware ROP/JOP bypass to get past ARM pointer authentication, (3) a kernel or EL2 escalation. If those three exist, the malicious controller becomes a clean post-exploitation trigger. Without them, all it does is send inputs.
Also i edited the text to make it more complete.

Also thats a theoretical delivery mechanism its not a working exploit and i chose joy cons because they are i think the most trusted hardware.
 
Last edited by Flipped_Out999,
  • Haha
Reactions: hippy dave
Just enter your question into any AI chatbot, free or paid, it really does not matter. You will quickly realize how incomplete your idea is on several levels. It seems you have completely ignored the cryptographic aspects of the problem as well as.. well .... any other aspect as well.

It is a bit like telling a neurosurgeon with a complex brain tumor issue, “Have you tried using a spoon?”
 
  • Haha
Reactions: BigOnYa and [Truth]
Just enter your question into any AI chatbot, free or paid, it really does not matter. You will quickly realize how incomplete your idea is on several levels. It seems you have completely ignored the cryptographic aspects of the problem as well as.. well .... any other aspect as well.

It is a bit like telling a neurosurgeon with a complex brain tumor issue, “Have you tried using a spoon?”
Thanks for pointing it out i will edit it and give explanations idk how the switch 2 kernel / OS works and i will do more research of will it work.
 
Just enter your question into any AI chatbot, free or paid, it really does not matter. You will quickly realize how incomplete your idea is on several levels. It seems you have completely ignored the cryptographic aspects of the problem as well as.. well .... any other aspect as well.

It is a bit like telling a neurosurgeon with a complex brain tumor issue, “Have you tried using a spoon?”
This comparison is perfection! 👌😄
 
  • Like
Reactions: BigOnYa
Status
Not open for further replies.

Site & Scene News

New Hot Discussed User Submitted