Null Pointer Dereference Vulnerability in Matter SDK by Connectivity Standards Alliance
CVE-2025-56363
7.5HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 14 July 2026
What is CVE-2025-56363?
A null pointer dereference vulnerability has been identified in the Matter SDK, specifically within the ReadRevisionAttribute function utilized across various clusters, including Channel, Account Login, and TargetNavigator. This vulnerability arises due to inadequate validation of the delegate pointer before it is dereferenced. A potential attacker could exploit this flaw by sending a specially crafted read request to the affected device, resulting in a denial of service and causing the device to crash. The issue has been validated in SDK versions prior to 1.4.0, emphasizing the need for prompt updates and mitigations for affected users and developers.
