Nintendo Switch 'severe vulnerability' patched — what you need to know

Nintendo switch oled
(Image credit: Tom's Guide)

We love all of the best Switch games, but playing first-party titles online may have been quietly risky over the past 12 months and more. That's because hackers could have exploited a vulnerably in online elements of the Switch, Nintendo 3DS and Wii U to compromise your playing experience, steal private information and even take complete control of your console. 

Known as ENLBufferPwn, this is exploit was given a score of 9.8/10 (critical) by the Common Vulnerability Scoring System used to measure such weaknesses. First found in 2021 and reported to Nintendo, the gaming giant has been been quietly fixing the vulnerability in leading titles like Nintendo Switch Sports, Mario Kart 8, and the Splatoon series throughout 2022 . First-party games were particularly vulnerable to a C++ buffer overflow in the Network Library, rendering them prime targets for those up to no good.

New security worries emerged after homebrew developer PabloMK7 tweeted they had discovered ENLBufferPwn in Mario Kart 7 on 3DS in December 2022 with a video demonstrating the hacking method. But as reported by Eurogamer, Nintendo has now fixed the issue for this game when it updated the title for the first time in a decade after PabloMK7 and others reported it via Nintendo's HackerOne program.  

Despite this quick fix, and the effective response to ENLBufferPwn throughout 2022, Nintendo owners should weigh up the risk of playing first-party games online right now. It should be safe to play with friends and trusted groups, but there could still be other vulnerable titles or another way for malicious hackers to take advantage of exploits. 

Switch gamers unsure if their online game of choice has been patched might want to stick to single-player titles such as the excellent The Legend of Zelda: Breath of the Wild. Those playing online on previous-gen consoles such as the 3DS or Wii U should be particularly wary as updates for games on these platforms are rare compared to the well-supported Switch.

Nintendo has not given an official comment on ENLBufferPwn, but keeping your software and hardware up to date with the latest versions is one of the best ways to protect yourself. And if you do experience any issues in a first or third-party game, make sure to report it to Nintendo as soon as possible.

Andy is a freelance writer with a passion for streaming and VPNs. Based in the U.K., he originally cut his teeth at Tom's Guide as a Trainee Writer before moving to cover all things tech and streaming at T3. Outside of work, his passions are movies, football (soccer) and Formula 1. He is also something of an amateur screenwriter having studied creative writing at university.

Read more
Best Nintendo Switch games
Best Nintendo Switch games for 2025
Screenshot from Super Mario Bros
The best Nintendo Switch multiplayer games in 2025
Mario Kart 8 Deluxe
Massive Nintendo Switch game sale from $14 — here’s 15 deals I’d buy from Amazon, Walmart and more
Switch 2 console and logo
New Nintendo patent teases a big upgrade for Switch 2 — here's what we know
Two Nintendo Switch consoles on a couch
Ahead of Switch 2's launch, Nintendo just made some huge changes to their discount schemes
Mario Kart 8 Deluxe screenshot
Massive Nintendo Switch game sale — 11 deals I'd buy from $14
Latest in Nintendo
Nintendo Switch 2
Nintendo Switch 2 — industry insider just tipped release month and launch plans
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy
Nintendo Switch 2
Nintendo Switch 2 — 7 biggest questions that need answers at Nintendo Direct April 2
Nintendo Switch 2
Nintendo Switch 2 — these are the 5 launch games that would make me buy on day one
The Legend of Zelda Tears of the Kingdom screenshot
Massive Nintendo Switch game sale live from $4 — 19 deals I'd buy now
Nintendo Switch 2
Nintendo Switch 2 just tipped for three display upgrades — here's what we know
Latest in News
AI Mode of google search
Google’s making it easier to start new AI Mode searches — here’s how
Gemini logo on smartphone
Google Gemini Gems now available to all users without a subscription
DeepSeek login in page displayed on smartphone
DeepSeek R1 just got even smarter with a new upgrade — here's what's changed
Galaxy S25 Ultra from the back
Samsung Galaxy S26 Ultra leak claims a massive upgrade is coming to all three cameras
CAD renders of the Google Pixel 10
Pixel 10 could include a repurposed ‘Pixie’ assistant — but what actually happened?
Galaxy S25 Edge dummy unit from side angle
Samsung Galaxy S25 Edge design just shown off on video from every angle with seemingly accurate dummies