Executive brief
Acer NitroSense is a system management utility for gaming laptops that runs with elevated privileges. An unauthenticated local attacker can connect to a debugging endpoint exposed on the local machine and execute arbitrary code with the application's privileges, leading to full system compromise.
Technical details
The vulnerability stems from Chromium remote debugging being enabled in the production Electron application, exposing the DevTools endpoint on localhost TCP port 9993 without authentication. An unprivileged local attacker can connect to this endpoint and execute arbitrary JavaScript in the privileged application context, bypassing all OS-level privilege isolation and achieving code execution with NitroSense's elevated permissions.
Affected products
- Acer NitroSense up to and including 5.2.63
Timeline
- 2026-09-23: disclosed