Junglewise Threat Intelligence

CVE-2026-78806: Matter Project Chip information disclosure in commissioning

CVE-2026-78806 · Severity: medium · CVSS 5.5 · Published 2026-09-21

Executive brief

Matter is a wireless protocol that allows smart home devices to communicate securely across different manufacturers' ecosystems. A specification-implementation gap in Matter v1.5.1 allows an attacker on the same commissioning network to extract sensitive information during device setup without authorization. An attacker could intercept device pairing credentials or configuration details, potentially enabling unauthorized access to connected smart home systems.

Technical details

A flaw in the PerformCommissioningStep function in ChipDeviceController.cpp allows sensitive information leakage during the device commissioning process due to a specification-implementation gap. The vulnerability requires local/adjacent network access to the commissioning network and can be triggered during normal device pairing operations. The attacker gains access to credentials and configuration data exchanged during commissioning without requiring elevated privileges.

Affected products

  • Matter Project Chip 1.5.1

Timeline

  • 2026-09-21: disclosed

References