So they say the NS2 (Switch 2) is unhackable. Well, it's close. The attempts that were tried did reach userland code execution, but stopped one privilege ring short of the kernel.
So I came up with an idea of how to mod it (DISCLAIMER: put my idea in practice only if you give me credit for bringing it up. Also, I didn't check if anyone else thought the same as me — ideas like this converge fast, so verify before building). So the principle is simple: you build a spoofing device that impersonates a Joy-Con 2 over BLE, which sends a crafted HID report sequence when triggered by a click pattern. That sequence is meant to hit a memory-safety bug in the console-side input parser, which then loads unsigned homebrew from the microSD Express card (the slot exposes a real NVMe/PCIe link, so storage access is possible — execution is the hard part). Please point out the mistakes I made with my idea.
EDIT: the payload should be coded (cuz no firmware like that exists) and run on an external nRF52840 board flashing XD2Joy-style firmware to mimic a real Joy-Con 2, rather than burning anything into the official controller — its image is signature-verified and can only be updated through System Settings → Controllers & Accessories, so reprogramming it would first require defeating Nintendo's secure boot, which nobody has done. Also make sure the device stays fully functional as a normal controller until you activate the trigger, so the console sees nothing unusual.
SECOND EDIT (honest scope): this is not a jailbreak by itself. Everything above is step 4 of the chain. Steps 1–3 are unsolved and unpublished: (1) a memory-safety bug reachable from controller input reports in the HID/BT stack, (2) a PAC-aware ROP/JOP bypass to get past ARM pointer authentication, (3) a kernel or EL2 escalation. If those three exist, the malicious controller becomes a clean post-exploitation trigger. Without them, all it does is send inputs.
Also i edited the text to make it more complete.
Also thats a theoretical delivery mechanism its not a working exploit and i chose joy cons because they are i think the most trusted hardware.
So I came up with an idea of how to mod it (DISCLAIMER: put my idea in practice only if you give me credit for bringing it up. Also, I didn't check if anyone else thought the same as me — ideas like this converge fast, so verify before building). So the principle is simple: you build a spoofing device that impersonates a Joy-Con 2 over BLE, which sends a crafted HID report sequence when triggered by a click pattern. That sequence is meant to hit a memory-safety bug in the console-side input parser, which then loads unsigned homebrew from the microSD Express card (the slot exposes a real NVMe/PCIe link, so storage access is possible — execution is the hard part). Please point out the mistakes I made with my idea.
EDIT: the payload should be coded (cuz no firmware like that exists) and run on an external nRF52840 board flashing XD2Joy-style firmware to mimic a real Joy-Con 2, rather than burning anything into the official controller — its image is signature-verified and can only be updated through System Settings → Controllers & Accessories, so reprogramming it would first require defeating Nintendo's secure boot, which nobody has done. Also make sure the device stays fully functional as a normal controller until you activate the trigger, so the console sees nothing unusual.
SECOND EDIT (honest scope): this is not a jailbreak by itself. Everything above is step 4 of the chain. Steps 1–3 are unsolved and unpublished: (1) a memory-safety bug reachable from controller input reports in the HID/BT stack, (2) a PAC-aware ROP/JOP bypass to get past ARM pointer authentication, (3) a kernel or EL2 escalation. If those three exist, the malicious controller becomes a clean post-exploitation trigger. Without them, all it does is send inputs.
Also i edited the text to make it more complete.
Also thats a theoretical delivery mechanism its not a working exploit and i chose joy cons because they are i think the most trusted hardware.
Last edited by Flipped_Out999,










