Executive brief
NitroSense and PredatorSense are system monitoring applications for Acer gaming computers. The software contains a hard-coded AES encryption key that can be extracted and used by local attackers to decrypt protected information or perform unauthorized actions on the system.
Technical details
The vulnerability stems from the use of a hard-coded AES encryption key embedded in the Acer System Monitoring component. An attacker with local system access can extract this static key from the application binaries and use it to decrypt data that was intended to be protected by the encryption. This allows unauthorized access to sensitive information or manipulation of encrypted communications within the application. The attack requires local access to the system where NitroSense or PredatorSense is installed. No patch availability information is currently provided.
Affected products
- Acer NitroSense
- Acer PredatorSense
Timeline
- 2026-09-17: disclosed