CVE-2026-6924 HIGH

CVE-2026-6924: Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path

Vendor Silicon Labs
Product Silicon Labs Matter Github
Weakness CWE-336
Published July 23, 2026
Last update July 24, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.

Key dates

02Disclosure timeline

July 23, 2026 CVE published
July 24, 2026 Record updated