---
id: CVE-2026-50228
title: >-
  An unauthenticated local attacker can connect to the Electron DevTools
  endpoint exposed by Acer NitroSense software (versions up to and including
  5.2.63) on localhost TCP port 9993
summary: >-
  An unauthenticated local attacker can connect to the Electron DevTools
  endpoint exposed by Acer NitroSense software (versions up to and including
  5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is
  enabled in the pro…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U'
cwe:
  - CWE-489
vendor: Acer
product: NitroSense V5
affected:
  - nitrosense_v5 <= 5.2.63
published: '2026-09-23'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:15:28.037'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50228'
references:
  - url: 'https://community.acer.com/en/kb/articles/20051'
    label: 8fc372e3-d9c5-46e4-9410-38469745c639
tags:
  - nvd
  - cve.org
epss: 0.00134
epssPercentile: 0.02367
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T14:49:30.806462Z'
cvssSource: cna
ingestedAt: '2026-09-23T08:20:37.582Z'
---

## Overview

An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the production application, the attacker can execute JavaScript in the privileged application context and achieve arbitrary code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
