Hacker News new | ask | show | jobs
by mschuster91 1352 days ago
I thought that vulnerability was gone since at least September 2019 with the 2nd revision?
1 comments

It is, but the core vulnerability of the chipset (Tegra X1) still exists AFAIK. Granted, you need to hardmod to jailbreak a Mariko model (launch models can be softmodded), but that's basically the same thing that happened with the 3DS.
It's a different exploit. The original exploit is an issue with the Tegra's recovery mode (RCM), requiring a USB payload to be sent to the Switch at boot every time.

I believe the hardmod is a voltage glitching exploit, as described for the Vita here: https://yifan.lu/images/2019/01/Injecting_Software_Vulnerabi... . It is able to inject code through the onboard memory then load a payload from a memory card rather than USB.