A developer known as Gezine has discovered a new userland exploit that reportedly works on both the original Nintendo Switch and Nintendo Switch 2 without requiring an internet connection.
The breakthrough is notable because it avoids two limitations affecting earlier entry points. It does not rely on WebKit, and it does not require a modified save file to be transferred through Nintendo Switch Online.
Existing save-based methods can force players to connect to Nintendo’s online services. Doing so may require the console to install the latest firmware, which can close vulnerabilities before they are useful to homebrew developers.
Gezine’s method reportedly operates entirely offline and works across all current firmware versions. However, it only provides access at the userland level and does not give complete control over the console.
That means the discovery should not be described as a full Nintendo Switch 2 jailbreak.
| Detail | Reported information |
|---|---|
| Developer | Gezine |
| Supported systems | Nintendo Switch and Nintendo Switch 2 |
| Internet required | No |
| WebKit required | No |
| Save transfer required | No |
| Firmware support | Reportedly works across all versions |
| Access level | Userland |
| Full jailbreak | No |
| Possible future uses | Homebrew software, local save tools and emulation |
The exploit avoids Nintendo Switch Online requirements
Previous userland entry points have reportedly depended on modified save files.
Moving those files to a console can require the Nintendo Switch Online save transfer system. The problem is that Nintendo may require the system to be updated before allowing access to its network services.
A firmware update can patch the same vulnerability that the modified save is intended to use.
An offline entry point removes that conflict. A console can remain on its existing firmware while the exploit is tested, without connecting to Nintendo’s servers.
The method is also said to avoid WebKit, the browser technology commonly used as an entry point on other consoles and devices.
Nintendo Switch 2 reportedly protects this area with ARM Pointer Authentication Code technology. That defence makes some forms of code manipulation more difficult by checking whether protected pointers have been altered.
Gezine’s approach apparently enters through a different part of the system, though no detailed technical explanation was provided in the supplied report.
Userland access has important limitations
Userland is the area where normal applications operate.

An exploit at this level may allow unofficial code to run within a restricted environment, but it does not automatically provide access to the operating system kernel or the most protected hardware functions.
A complete jailbreak generally requires additional vulnerabilities that allow developers to escape the application environment, bypass deeper security protections and gain broader system privileges.
Without those additional stages, the new entry point may remain limited in what it can do.
It could still become an important foundation for future homebrew work. Developers often begin with userland access before finding other weaknesses that expand control.
There is no confirmation that Gezine or another developer has discovered a kernel-level exploit for Nintendo Switch 2.
Homebrew could begin with smaller applications
If the entry point becomes stable and publicly usable, early homebrew software would probably focus on relatively basic functions.
Possible examples include local save management, simple utilities, media applications and retro emulators that operate within the available restrictions.
More advanced software would depend on how much memory, processing access and storage control the exploit provides.
Homebrew should also be separated from piracy. Unofficial applications can be used for preservation, accessibility, development experiments and personal tools without distributing copyrighted games.
Nintendo has historically responded aggressively to software and hardware used to bypass its security systems, especially when the same methods support piracy.
Anyone experimenting with unofficial software also faces practical risks. Consoles can become unstable, save data can be damaged, and online access may be restricted if Nintendo detects unauthorised modifications.
Nintendo continues strengthening Switch 2 security
Nintendo has released regular firmware updates for Switch 2 as it works to close vulnerabilities and limit unauthorised software.
The company has strong commercial reasons to maintain tight control over the platform.
Console security protects game sales, online services, account information and agreements with third-party publishers. It also reduces cheating in multiplayer games and limits the use of modified software on public networks.
An exploit that works offline across multiple firmware versions is harder to address than one tied to a single browser or save-transfer process.
Nintendo could still patch the underlying vulnerability once it understands the entry point. Future consoles may ship with updated firmware, while existing systems could lose compatibility after installing a new version.
The claim that the exploit works on every firmware version reflects its reported status at the time of disclosure. It does not guarantee that later updates will remain vulnerable.
The original Switch shows what homebrew could eventually achieve
The first Nintendo Switch developed a large homebrew community after researchers gained deeper access to the hardware.
Modified systems have been used for emulation, custom operating systems, game modifications and experimental software.
Developers have also managed to run PC applications and games through unofficial configurations, although performance and compatibility vary widely.
Switch 2 is a newer and more secure system, so similar results should not be expected immediately.
The new userland exploit represents an entry point rather than a completed modification platform. Considerable additional research would be required before the system could run the same range of unofficial software available on a fully modified original Switch.
Public availability has not been confirmed
The supplied report does not state whether Gezine plans to publish the exploit, provide demonstration code or limit the information to other security researchers.
Responsible disclosure could also give Nintendo time to investigate and patch the vulnerability before technical details become widely available.
Even if the exploit is eventually released, ease of use will matter. A method that requires specialist hardware or advanced technical knowledge would have less impact than one that can be launched through ordinary console features.
For now, the discovery is a significant step for the Nintendo Switch 2 homebrew community because it reportedly offers an offline, firmware-independent userland entry point.
It does not unlock the full console, and there is no confirmed public jailbreak. Its importance lies in giving researchers a new place to begin while Nintendo continues updating the system’s security.



Discussion (0)
Be the first to comment.