---
id: CVE-2025-56363
title: >-
  A null pointer dereference vulnerability exists in the Matter SDK
  (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function
  used in multiple clusters (Channel, Account Login, TargetNavigator, etc.)
summary: >-
  A null pointer dereference vulnerability exists in the Matter SDK
  (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function
  used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The
  function lacks …
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: csa-iot
product: matter
affected:
  - matter < 1.4.0.0
patched:
  - matter 1.4.0.0
published: '2026-07-14'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:38:41.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-56363'
references:
  - url: 'https://github.com/project-chip/connectedhomeip/'
    label: cve@mitre.org
  - url: 'https://github.com/project-chip/connectedhomeip/issues/39173'
    label: cve@mitre.org
  - url: 'https://github.com/project-chip/connectedhomeip/issues/39173'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00588
epssPercentile: 0.46234
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-05T17:36:48.960049Z'
ingestedAt: '2026-10-05T18:29:11.171Z'
---

## Overview

A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks proper validation of the delegate pointer before dereferencing. A remote unauthenticated attacker can exploit this issue by sending a crafted read request, causing the device to crash (denial of service). This issue has been confirmed in SDK version v1.4 (commit ab3d5ae).

## Affected

- `matter < 1.4.0.0`

## Remediation

Upgrade past the affected range:

- `matter 1.4.0.0`
