Remote Code Execution Vulnerability in Acer NitroSense Software
CVE-2026-50228

6.1MEDIUM

Key Information:

Vendor

Acer

Vendor
CVE Published:
23 September 2026

What is CVE-2026-50228?

Acer NitroSense software has a vulnerability that allows unauthorized local attackers to access the exposed Electron DevTools endpoint on localhost TCP port 9993. Due to the enabled Chromium remote debugging feature in the production application, an attacker can execute arbitrary JavaScript code within the context of the application, potentially leading to severe security breaches.

Affected Version(s)

NitroSense V5 Windows * <= 5.2.63

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tolga Cöhce
.