CVE-2026-50228: Electron DevTools Arbitrary Code Execution Vulnerability in NitroSense
An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the production application, the attacker can execute JavaScript in the privileged application context and achieve arbitrary code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Acer NitroSenseto a version that resolves this vulnerability.Fixed in 5.2.84
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker with local access to the affected system can connect to the DevTools endpoint on localhost. Remote network access is not indicated by the available information.
What access or conditions are required for exploitation?
The attacker needs the ability to make a local TCP connection to port 9993 and interact with the Electron DevTools endpoint. No authentication is required.
Which installations are affected?
Acer NitroSense versions up to and including 5.2.63 are identified as affected. The exposed endpoint is on localhost TCP port 9993 and results from Chromium remote debugging being enabled in the production application.
How can I check whether a system is exposed?
Check the installed Acer NitroSense version and determine whether it is 5.2.63 or earlier. Also verify whether a local listener is present on TCP port 9993.