CVE-2026-6924

Silicon Labs · Silicon Labs Matter Github

A vulnerability in the entropy initialization for SiWx917 within the Silicon Labs Matter implementation causes the Deterministic Random Bit Generator (DRBG) to use a predictable seed.

Executive summary

A critical cryptographic flaw in the Silicon Labs Matter implementation leads to predictable random number generation, significantly undermining secure communications.

Vulnerability

The issue is a result of using a static or predictable seed for the pseudo-random number generator (CWE-336), which weakens the cryptographic security of the affected SiWx917 hardware.

Business impact

The CVSS score of 8.7 highlights the severe impact on product security, as predictable random values render cryptographic operations insecure. This could allow attackers to predict session keys, bypass authentication, or decrypt sensitive data transmitted by devices using this implementation, leading to widespread device compromise.

Remediation

Immediate Action: Review the vendor documentation provided at the Silicon Labs portal and update to the version that addresses the entropy initialization flaw.

Proactive Monitoring: Audit device communication logs for patterns that may indicate predictable or repeating cryptographic nonces or keys.

Compensating Controls: Where possible, isolate affected IoT devices on restricted network segments to mitigate the risk of remote exploitation while awaiting firmware updates.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a fundamental failure in the device's security architecture. All organizations utilizing Silicon Labs SiWx917 hardware within their Matter ecosystem must prioritize the identification of affected units and ensure that firmware updates are applied immediately upon release.