The GlitchMod knowledge base

Fusée Gelée

Fusée Gelée is a vulnerability for the Nvidia Tegra series of System-on-a-Chip platforms, where the USB software stack in its bootROM can be exploited in Tegra's recovery mode. The bootROM is read-only memory built into the Tegra processor…

2 min readUpdated Oct 9, 2026

Fusée Gelée is a vulnerability for the Nvidia Tegra series of System-on-a-Chip platforms, where the USB software stack in its bootROM can be exploited in Tegra's recovery mode. The bootROM is read-only memory built into the Tegra processor which is first loaded into the application stack prior to loading the operating system. A stack buffer overflow is done by sending a specially crafted payload via USB during boot-up, which overrides the application stack holding the bootROM, to which unsigned code can be executed from a frozen state.

This can be achieved through the Tegra's internal recovery mode (named RCM, a shortened form of 'ReCovery Mode'), which was used by Nintendo for servicing Switch units, under the assumption that the console was damaged. Holding down Vol (+) and POWER, in conjunction with pins 7 and 10 shorted on the 2nd Joy-Con port, using either a printed/pre-made jig or a paperclip, will enter the recovery state before the bootROM.

For end users, it allowed for access to CFW and homebrew on Nintendo Switches manufactured before the exploit disclosure, even without soldering.

After these findings were discovered, around July 2018, Nintendo began quietly shipping revised new versions of the Nintendo Switch with new Tegra X1 chips that featured an updated irom patch 3 that fixed the RCM exploit through limiting the size of wLength for USB control requests in RCM to only 255 bytes.[1] The only way to exploit a non-RCM vulnerable console would be to install a modchip that uses voltage glitching, which requires hands-on experience with micro soldering.

The original writeup of the Fusée Gelée exploit can be found in this document released by ReSwitched from around April 2018.

References