There isn't going to be an exploit so there isn't anything on topic to discussCan we get back to the topic at hand, please?
Dunno about the last couple of updates, but older ones have userland webkit exploits. SciresM and Comex were discussing it... not very useful without a kexploit, but getting r/w in the browser is a start...There isn't going to be an exploit so there isn't anything on topic to discuss
Dunno about the last couple of updates, but older ones have userland webkit exploits. SciresM and Comex were discussing it... not very useful without a kexploit, but getting r/w in the browser is a start...
This is a demo of a transferred hax savegame from switch 1 working on switch 2. I helped retr0id with setting this up months ago, and it working was expected.I dont want to be the first comment after sciresM since I highly respect your work and input.
No Bluesky embedder
But Is this legit and what does this mean?
First userland exploit?
Message by SciresM on Reddit:Dunno about the last couple of updates, but older ones have userland webkit exploits. SciresM and Comex were discussing it... not very useful without a kexploit, but getting r/w in the browser is a start...
This kind of post is inane. Are you really posting a...random Japanese commentary on a short discord interaction?
Anyway; this is meaningless for end users, does not represent significant progress anyone here should care about.
I have been helping Hexkyz work on WebKit stuff so he can look at 19.0.0 because he's a friend and it's fun. Affirming that I am not making a cfw for switch 2 even if it gets hacked.
WebKit is known hackable and the existence of bugs in it isn't news. It's just high effort.
It doesn't grant interesting new capabilities over retr0id's rop in any sense that literally anyone here would care about.
This sub is a dumpster, man.
Also chiming in that I and others have audited the kernel and found no bugs. Comex hasn't audited it yet, and I'm always happy for fresh eyes, but it's overwhelmingly likely nothing will be found.
Most of the above still stands (kernel exploit will likely never be found), and the note from Reddit addresses the one I was talking about... but the first quote you made, has nothing to do with what I was talking about. I either didn't know, or completely forgot about a hax save thing... so being locked into the Switch 1 sandbox doesn't really apply here. I think.This is a demo of a transferred hax savegame from switch 1 working on switch 2. I helped retr0id with setting this up months ago, and it working was expected.I dont want to be the first comment after sciresM since I highly respect your work and input.
No Bluesky embedder
But Is this legit and what does this mean?
First userland exploit?
This means essentially nothing for end users. This gives ROP under a switch 1 game process, which is very heavily sandboxed. You cannot load or run custom code executables or interact with anything the switch 1 game cannot...Post automatically merged:
Message by SciresM on Reddit:
To me it doesn't sound implausible. It would need custom hardware though, because something like that has already been done on the PC world several years ago: hackintosh.Most of the above still stands (kernel exploit will likely never be found), and the note from Reddit addresses the one I was talking about... but the first quote you made, has nothing to do with what I was talking about. I either didn't know, or completely forgot about a hax save thing... so being locked into the Switch 1 sandbox doesn't really apply here. I think.
But yea... tiny kernel with no vulnerabilities, and anti-glitching stuff in hardware. Game over, I think.

Already done and ended on a bricked console displaying a message about do not temper with the hardware.literally solder it a new nand directly to the SoC and start reading the requests with a probe. Then start interacting with the SoC to get the right hook for the bootloader to load and begin from there.
URL?Already done and ended on a bricked console displaying a message about do not temper with the hardware.

Here on GBATemp, about the first tryouts of mess with the console.URL?

At least, they put a max of chance in their pocket in doing so.Wonder if the fact that nintendo started doing bug bounties aided in the decline of the scene in any way.
Don't confuse BSD with FreeBSDTo me it doesn't sound implausible. It would need custom hardware though, because something like that has already been done on the PC world several years ago: hackintosh.
You see, when OS X was first ported to intel, it shared many features that you mention: tiny microkernel (based on BSD too, like the HOS kernel), anti-piracy stuff in hardware AND kernel extension (Don't Steal MacOS.kext or DSMOS), custom SMBIOS and custom EFI bootloader.
What hackers did back then was literally EMULATE all that stuff (even the bootloader).
So... if the Switch 2 has that many (or even more) lock, the most logical way to "hack" it would be to literally solder it a new nand directly to the SoC and start reading the requests with a probe. Then start interacting with the SoC to get the right hook for the bootloader to load and begin from there.
- The bootloader required a special key? they emulated it via software
- The kernel wouldn't boot or give panic if the anti-tamper chip wasn't found? they created a kernel extension that literally emulated that (VirtualSMC.kext)
- The kernel required a unique serial number and model to even work? they created an SMBIOS injector at bootloader level
Remember: NOTHING is unhackable.
you forgot to turn off the wifi i thinkHere on GBATemp, about the first tryouts of mess with the console.
Well in that case, Now i really wana hack it!IDK if is was a good idea to hack the switch 2 because Nintendo becoming mad.![]()

Better looks find the exploit. But my Switch 2 I don't touch it for guarantee and the ban by big-n. If the exploit was the same that the Switch 1, I drop my hat.Well in that case, Now i really wana hack it!![]()

I bought 2 so not going to try anything till the exploit is known to work.Better looks find the exploit. But my Switch 2 I don't touch it for guarantee and the ban by big-n. If the exploit was the same that the Switch 1, I drop my hat.![]()

I give you 10 bucks and is my lost!At this Point i really think about selling the Switch again. Seems Most Games still have a Switch 1 Version.