

Exploits a vulnerability in arm9loader to execute ARM9 code directly at boot (arm9loaderhax.bin).Requires an exploit on ≤9.2 in order to install must be built from source, using the console-specific OTP hash.Exploit discovered by WulfyStylez, Dazzozo, shinyquagsire23, plutoo, Normmatt, and yellows8. It was used by flashcart manufacturers after the MSET exploit was patched. This exploit works up to version 9.2.0 and grants kernel level access.

When launching the 3DS System Settings application's DS profile settings editor, it will cause the application that edits the DS profile to crash, and this crash pushes custom code into memory from within the edited profile and makes the security co-processor "accidentally" load that code, resulting in homebrew being launched. To exploit this vulnerability, you need a working DS Mode flashcart for your 3DS and you must run an NDS Homebrew designed to alter the DS Profile settings strings. This exploit is also used by Flashcart manufacturers to take over the 3DS's kernel. This exploit only works on 3DS System Software version 4.1.x to 4.5.x Yes, same exploits as ≥9.3 but no need to. Yes, use SysUpdater CIA (on EmuNAND) or 3dsx (on SysNAND from Homebrew Launcher)

Yes, use DSiWare or Hardmod to install CFW then downgrade. Yes, use a CFW with signature checks disabled to install unsigned CIAs Yes, use a DS flashcart (blocked carts can be unblocked with CFW and/or patched TWL_FIRM) Yes, use a DS flashcart (Supercard DSTWO/R4i Gold) Yes, use NTR CFW, HANS, a flashcart, or install as a CIA Yes, use a flashcart (Hans only on New 3DS) Install out-of-region eShop content (like DLC)? Yes, buy a Sk圓DS and play ROMs from that. Yes, as long as the game doesn't require an update Go online with a game from another region? Yes, use the region free launcher of The Homebrew Launcher Run games from other regions (regionfree)? Yes, use SaveDataFiler or JK's SaveManager for 3DS games, TWLSaveTool for retail DS cartridges Yes, use svdt for 3DS games, TWLSaveTool for retail DS cartridges Yes (convert to firm format or convert an A9LH boot manager to bin.) Yes (same exploits as ≥9.3, plus Homebrew Launcher loader CIA) Yes, use FreakyHax, Ninjhax, Soundhax or a previously installed exploit to run the Homebrew Launcher. No A9LH or sighax/B9S installed (unhacked system)
