{"id":"CVE-2026-78806","published":"2026-09-21T22:16:58.733","lastModified":"2026-09-24T14:18:17.497","description":"An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component","cvssScore":5.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://csa-iot.org/developer-resource/specifications-download-request/","tags":[]},{"url":"https://github.com/Anonymous241429/Matter","tags":[]},{"url":"https://github.com/project-chip/connectedhomeip/","tags":[]}],"exploitRefs":[{"url":"https://github.com/Anonymous241429/Matter","tags":[]},{"url":"https://github.com/project-chip/connectedhomeip/","tags":[]}],"hasPoc":true,"ai":null}