Tech »  Topic »  Grafana Patches Chromium Bugs, Including Zero-Day Exploited in the Wild

Grafana Patches Chromium Bugs, Including Zero-Day Exploited in the Wild


Grafana has rolled out security updates to address four high-severity vulnerabilities in the Chromium library used in the Grafana Image Renderer plugin and Synthetic Monitoring Agent.

The most important of these issues is CVE-2025-6554, a type confusion in Chrome’s V8 JavaScript engine that could be exploited remotely to perform arbitrary read/write operations, which was exploited in the wild as a zero-day.

“Google is aware that an exploit for CVE-2025-6554 exists in the wild,” Google said last week, when it announced that Chrome versions 138.0.7204.96/.97 for Windows, versions 138.0.7204.92/.93 for macOS, and version 138.0.7204.96 for Linux contain patches for the bug.

Grafana also released patches for CVE-2025-5959, a type confusion bug in the V8 engine that could allow remote attackers to execute arbitrary code within the sandbox, using crafted HTML pages.

Google resolved the issue in Chrome versions ...


Copyright of this story solely belongs to securityweek . To see the full text click HERE