Browserhax exploit for ipatched Switch hardware will be out later this week

help_6001488428918.png

While prospects for homebrew on newer Nintendo Switch hardware, "ipatched" units, have been fairly bleak, it appears that a new exploit will be here soon. Mike Heskin (hexkyz) has confirmed that a method for users on current Switch hardware is set to be released later this week. Browserhax + nvhax will allow for ipatched systems below OFW 6.2.0 to access userland and use homebrew. This is far more limited than what can be done on unpatched units, but it marks the first breakthrough for newer hardware. Projects that work through userland mode can be found in GBAtemp's emulation, homebrew, and software projects section, and this also means you'll be able to utilize homebrew made for the bounty.


 
That's totally a bug and not an overlooked feature.
Well, I'm not too sure of the technical side of things. However, is running unofficial code a bug?... Or an unintended feature? Did it involve a complex workaround to take advantage of, or could we just build third party tools right off the bat? These are all serious questions as I'm still hazy about it.
 
Well, I'm not too sure of the technical side of things. However, is running unofficial code a bug?... Or an unintended feature? Did it involve a complex workaround to take advantage of, or could we just build third party tools right off the bat? These are all serious questions as I'm still hazy about it.
It is most certainly a bug. Here is a writeup authored by Kate Temkin: https://misc.ktemkin.com/fusee_gelee_nvidia.pdf

Unless I am misunderstanding what you're saying, in which case I apologize. :unsure:
 
  • Like
Reactions: Friendsxix


Sorry about that.
In case anyone is interested in knowing which bugs make up the exploit chain that will be released:
https://switchbrew.org/wiki/Switch_System_Flaws#System_Modules (see nvhax)
https://switchbrew.org/wiki/Switch_Userland_Flaws (see CVE-2016-4622)
 
I'm deeply sorry if this was discussed already, but does this mean that the patched Switches on market now, will be able to run CFW?
Only userland access means no CFW a la SX or am I wrong?
 
Last edited by MyconMama,
Can i use this to edit my save files for games like zelda BOTW
As much as I'd also love this, not currently.

We (will) only have user land access from within the browser, which would not have access to the save files for games.

With luck, someone will find an exploit to escape the browser sandbox and get generic file system access.
But wouldn't hold your breath.
 
As much as I'd also love this, not currently.

We (will) only have user land access from within the browser, which would not have access to the save files for games.

With luck, someone will find an exploit to escape the browser sandbox and get generic file system access.
But wouldn't hold your breath.
Are you sure? I swear when I used PegaSwitch on 3.0.0 before all this CFW fun, I could grab saves, albeit via some wonky script that took some effort. Is this going to be different to how PegaSwitch was then?
 
Are you sure? I swear when I used PegaSwitch on 3.0.0 before all this CFW fun, I could grab saves, albeit via some wonky script that took some effort. Is this going to be different to how PegaSwitch was then?

Hmm taking another look at the write up it does look possible. But @hexkyz would have to confirm as he doesn't specifically mention in his write up the control nvservices has from this point of view
.
Looks like it can write anywhere to DRAM (with some handle exhaustion/mem tricks), which hopefully will mean escaping sandbox protections.
Also, the home brew may need to be written specifically for this mode of exploit (or someone makes a new loader.

Happy to be completely corrected! Haven't been around the switch scene long
 

Site & Scene News

Popular threads in this forum