---
id: CVE-2025-56364
title: >-
  A use of uninitialized value vulnerability exists in the Matter SDK
  (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()`
  method is called without first checking whether a value exists
summary: >-
  A use of uninitialized value vulnerability exists in the Matter SDK
  (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()`
  method is called without first checking whether a value exists. This leads to
  a crash when an…
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-457
vendor: csa-iot
product: matter
affected:
  - matter < 1.4.0.0
patched:
  - matter 1.4.0.0
published: '2026-07-14'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:36:39.243'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-56364'
references:
  - url: 'https://github.com/project-chip/connectedhomeip/'
    label: cve@mitre.org
  - url: 'https://github.com/project-chip/connectedhomeip/issues/36711'
    label: cve@mitre.org
  - url: 'https://github.com/project-chip/connectedhomeip/pull/36729'
    label: cve@mitre.org
  - url: 'https://github.com/project-chip/connectedhomeip/issues/36711'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00583
epssPercentile: 0.45989
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-05T17:46:23.075961Z'
ingestedAt: '2026-10-05T18:29:11.171Z'
---

## Overview

A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value exists. This leads to a crash when an InvokeCommand is sent without initializing the destination group ID. The issue affects all versions before commit 0360cc3 (Dec 5, 2024) and leads to denial of service through SIGABRT. It is fixed by adding a .HasValue() check before access.

## Affected

- `matter < 1.4.0.0`

## Remediation

Upgrade past the affected range:

- `matter 1.4.0.0`
