CVE-2026-50228
Electron DevTools Arbitrary Code Execution Vulnerability in NitroSense
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the production application, the attacker can execute JavaScript in the privileged application context and achieve arbitrary code execution.
| CWE | CWE-489 |
| Vendor | acer |
| Product | nitrosense v5 |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for acer nitrosense v5
Be the first to know when new unknown vulnerabilities affecting acer nitrosense v5 are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Acer / NitroSense V5
* β€ 5.2.63
References
Credits
π Tolga CΓΆhce