Nintendo is cracking down hard on piracy, even when it comes to games released 30–40 years ago, and it’s doing the same with the Switch 2.
Nintendo continues to emphasize the security of the Switch 2 through regular firmware updates. However, the modding scene for the Japanese company’s current-generation console reached a significant milestone earlier this month. A developer named Gezine discovered a user-level vulnerability in the Nintendo Switch and Switch 2 that bypasses the limitations of existing entry points. This makes it more likely than ever to run homebrew software on the console.
Gezine confirmed the breakthrough on Twitter, stating that they created a user-level vulnerability for the Switch 1/2 that is not a WebKit- or save-based vulnerability. This new vulnerability differs from previous ones, as existing user-level vulnerabilities rely on save file vulnerabilities, which can’t be exploited without transferring saves via the Nintendo Online Service. A connection to the Nintendo Switch Online service is required for this transfer, forcing users to update the system firmware to the latest version. This update will likely fix the vulnerabilities that homebrew software could exploit.
By operating entirely offline and not forcing code execution through WebKit (which is reinforced by the Nintendo Switch 2’s ARM PAC, or Pointer Authentication Code), Gezine created a user-level entry point that works on all firmware versions. This new user-level vulnerability does not constitute a full Nintendo Switch 2 jailbreak on its own. However, it is a significant step because it provides a solid starting point for the homebrew scene. It could potentially pave the way for backing up local save files, retro emulation on the go, and basic homebrew software.
When we consider what has already been achieved with a modified Nintendo Switch, including running PC versions of games like Final Fantasy VII Remake, there are plenty of reasons to be excited about future developments.
Source: WCCFTech
I created switch 1/2 userland exploit that is not webkit or save exploit
“But we already have userland exploit from day 1”
The difference is existing userland exploit is based on save exploit which can’t be used without save transfer using Nintendo Online ServiceWhich forces… pic.twitter.com/7gNuaYXiIS
— Gezine (@gezine_dev) July 8, 2026



