Browserhax exploit for ipatched Switch hardware will be out later this week

help_6001488428918.png

While prospects for homebrew on newer Nintendo Switch hardware, "ipatched" units, have been fairly bleak, it appears that a new exploit will be here soon. Mike Heskin (hexkyz) has confirmed that a method for users on current Switch hardware is set to be released later this week. Browserhax + nvhax will allow for ipatched systems below OFW 6.2.0 to access userland and use homebrew. This is far more limited than what can be done on unpatched units, but it marks the first breakthrough for newer hardware. Projects that work through userland mode can be found in GBAtemp's emulation, homebrew, and software projects section, and this also means you'll be able to utilize homebrew made for the bounty.


 

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,004
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,135
Country
United States
That's totally a bug and not an overlooked feature.
Well, I'm not too sure of the technical side of things. However, is running unofficial code a bug?... Or an unintended feature? Did it involve a complex workaround to take advantage of, or could we just build third party tools right off the bat? These are all serious questions as I'm still hazy about it.
 

Friendsxix

Introspective Potato
Member
Joined
May 6, 2008
Messages
266
Trophies
1
Location
Best Hemisphere
XP
2,696
Country
United States
Well, I'm not too sure of the technical side of things. However, is running unofficial code a bug?... Or an unintended feature? Did it involve a complex workaround to take advantage of, or could we just build third party tools right off the bat? These are all serious questions as I'm still hazy about it.
It is most certainly a bug. Here is a writeup authored by Kate Temkin: https://misc.ktemkin.com/fusee_gelee_nvidia.pdf

Unless I am misunderstanding what you're saying, in which case I apologize. :unsure:
 

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,004
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,135
Country
United States
  • Like
Reactions: Friendsxix

_hexkyz_

Well-Known Member
Newcomer
Joined
Oct 4, 2018
Messages
60
Trophies
0
XP
447
Country
United States


Sorry about that.
In case anyone is interested in knowing which bugs make up the exploit chain that will be released:
https://switchbrew.org/wiki/Switch_System_Flaws#System_Modules (see nvhax)
https://switchbrew.org/wiki/Switch_Userland_Flaws (see CVE-2016-4622)
 

radicalwookie

Well-Known Member
Member
Joined
Sep 15, 2018
Messages
528
Trophies
0
Age
46
XP
1,210
Country
United States
I'm deeply sorry if this was discussed already, but does this mean that the patched Switches on market now, will be able to run CFW?
Only userland access means no CFW a la SX or am I wrong?
 

MyconMama

Well-Known Member
Newcomer
Joined
Dec 20, 2018
Messages
48
Trophies
0
Age
55
XP
245
Country
United Kingdom
Last edited by MyconMama,

MicShadow

Well-Known Member
Member
Joined
Jan 28, 2008
Messages
465
Trophies
0
Website
Visit site
XP
232
Country
Can i use this to edit my save files for games like zelda BOTW
As much as I'd also love this, not currently.

We (will) only have user land access from within the browser, which would not have access to the save files for games.

With luck, someone will find an exploit to escape the browser sandbox and get generic file system access.
But wouldn't hold your breath.
 

Scarlet

Onion Soup
Editorial Team
GBAtemp Patron
Joined
Jan 7, 2015
Messages
5,144
Trophies
2
Location
Middleish North-Right
Website
scarlet.works
XP
14,769
Country
United Kingdom
As much as I'd also love this, not currently.

We (will) only have user land access from within the browser, which would not have access to the save files for games.

With luck, someone will find an exploit to escape the browser sandbox and get generic file system access.
But wouldn't hold your breath.
Are you sure? I swear when I used PegaSwitch on 3.0.0 before all this CFW fun, I could grab saves, albeit via some wonky script that took some effort. Is this going to be different to how PegaSwitch was then?
 

MicShadow

Well-Known Member
Member
Joined
Jan 28, 2008
Messages
465
Trophies
0
Website
Visit site
XP
232
Country
Are you sure? I swear when I used PegaSwitch on 3.0.0 before all this CFW fun, I could grab saves, albeit via some wonky script that took some effort. Is this going to be different to how PegaSwitch was then?

Hmm taking another look at the write up it does look possible. But @hexkyz would have to confirm as he doesn't specifically mention in his write up the control nvservices has from this point of view
.
Looks like it can write anywhere to DRAM (with some handle exhaustion/mem tricks), which hopefully will mean escaping sandbox protections.
Also, the home brew may need to be written specifically for this mode of exploit (or someone makes a new loader.

Happy to be completely corrected! Haven't been around the switch scene long
 
D

Deleted User

Guest
Since this isn’t a CFW exploit, I won’t get banned from online services right?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: aeiou