儘管任天堂近幾個月來不斷加碼新一代主機的安全防護,但知名開發者Gezine剛剛完成了一項看似不可能的壯舉:他成功打造了一個同時適用於初代Switch與Switch 2的「萬能鑰匙」漏洞。對於任天堂而言,最致命的威脅在於這個漏洞是100%純離線運行的。
I created switch 1/2 userland exploit that is not webkit or save exploit "But we already have userland exploit from day 1" The difference is existing userland exploit is based on save exploit which can't be used without save transfer using Nintendo Online Service Which forces you to be at latest fw So even if kexploit or some sw based privilege escalation is found 99% people can't use save exploit. But this one works without any restriction and works at all fw Why not hack the webkit? Switch 2 webkit has Arm PAC(Pointer Authentication Code) that prevents ROP code execution So I avoided it as there was more easy one to exploit it

以往的黑客攻擊往往依賴網頁瀏覽器或上傳存檔至任天堂雲端,這通常會強制主機更新到最新固件,從而被官方順手修補。但Gezine的新方案完全繞開了這些依賴,這意味著無論主機處於哪個系統版本,該漏洞都能穩定觸發。雖然目前這還不算是一個完整的越獄(Jailbreak),但它正是整個破解社區苦尋已久的「萬能鑰匙」。


有了這個穩固的底層入口,未來在Switch 2上運行自製軟體(Homebrew)和復古模擬器將變得切實可行。任天堂現在正面臨著一個極其嚴峻的安全危機,這場貓鼠遊戲才剛剛開始。






