Just eleven days have passed since the Nintendo Switch debuted on the market. In general, we can talk about a successful launch, but like any first-generation product, a sharp edge or two will always appear. This time, it’s about the software. Technically, the Nintendo Switch does not come with a browser, but it has a module that behaves like one to enable access to certain WiFi networks. The problem? That module is based on a very old version of WebKit, and all the hackers needed was to recycle an old iOS exploit.
Console hacking is inevitable. Sooner or later, hardware and software enthusiasts start studying their designs from top to bottom, and doing things that would never have crossed manufacturers’ minds. Of course, any ideas about hacking, modding, emulation, and alternative code execution are officially rejected, but all complaints fall by the wayside. At the end of the day, the console owner does what they want with it, and if that means running Linux, installing an emulator, or replacing its hard drive with an SSD when it’s theoretically impossible, so be it. The recent launch of the Switch has turned Nintendo’s new platform into a very tempting target, and with the start of the week, the first vulnerability has already emerged.
Now, we must emphasize the term “vulnerability”. This is not a custom firmware, nor anything that allows running cartridge dumps (for now). In simple terms, the Nintendo Switch’s online mode is a work in progress, and things are expected to improve with each new update. Nintendo has stated on more than one occasion that the Switch would not have a traditional browser; however, the truth is that there is one integrated browser, based on WebKit. This browser activates when the user connects the console to a WiFi network that requires manual authentication or confirmation (for example, through a captive portal). The problem is that this browser uses a very old version of WebKit, which carries a memory corruption bug, CVE-2016-4657. The bug served as a starting point for the iOS 9.3 jailbreak, and dates back to August last year.
The big question here is what Nintendo was thinking when it decided to implement a version of WebKit that is more than six months old and full of holes. The next step will obviously be to release an update, but until that happens, hackers will look for additional vulnerabilities that lead to privilege escalation.