Impact
The vulnerability allows a local adversary to read sensitive data by invoking the PerformCommissioningStep routine inside ChipDeviceController.cpp. This function is part of the Matter standard’s commissioning flow, and the implementation gap means that private information can be retrieved without proper authentication checks. The flaw does not enable remote exploits or privilege escalation but does expose data that could be used to further compromise the device or network.
Affected Systems
This issue is present in Matter Project Chip version 1.5.1 and any deployments that rely on that version of the Matter Standard Specification. Devices that implement this version of the commissioning logic are susceptible while they are physically accessible to an attacker.
Risk and Exploitability
The vulnerability has no publicly available EPSS score and is not listed in CISA KEV. Because it requires local access, the exploitation probability is limited to scenarios where an attacker can physically reach the device or gain local network access. The lack of a CVSS score means the exact severity is not formally quantified, but the disclosed local information exposure can aid further attacks and is considered a medium‑to‑high risk based on the potential data at stake.
OpenCVE Enrichment