CVE-2026-50228: Electron DevTools Arbitrary Code Execution Vulnerability in NitroSense

Published Sep 23, 2026
·
Updated

An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the production application, the attacker can execute JavaScript in the privileged application context and achieve arbitrary code execution.

Affected Software

1 affected component
Acer NitroSense<=5.2.63

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Acer NitroSense to a version that resolves this vulnerability.

    Fixed in 5.2.84

Event History

Sep 23, 2026
CVE Published
via MITRE·07:20 AM
Data Sourced
via MITRE·07:20 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated attacker with local access to the affected system can connect to the DevTools endpoint on localhost. Remote network access is not indicated by the available information.

2

What access or conditions are required for exploitation?

The attacker needs the ability to make a local TCP connection to port 9993 and interact with the Electron DevTools endpoint. No authentication is required.

3

Which installations are affected?

Acer NitroSense versions up to and including 5.2.63 are identified as affected. The exposed endpoint is on localhost TCP port 9993 and results from Chromium remote debugging being enabled in the production application.

4

How can I check whether a system is exposed?

Check the installed Acer NitroSense version and determine whether it is 5.2.63 or earlier. Also verify whether a local listener is present on TCP port 9993.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203