Grafana Labs has addressed four Chromium vulnerabilities in critical security updates for the Grafana Image Renderer plugin and Synthetic Monitoring Agent. The Synthetic Monitoring Agent is part of Grafana Cloud's Synthetic Monitoring, used by customers who need custom probe locations, low-latency, high-visibility checks from internal nodes, and enterprises with hybrid or multi-cloud infrastructure needing synthetic tests behind firewalls. The Grafana Image Renderer is a widely deployed plugin in production environments where automated dashboard rendering for scheduled email reports and embedding in third-party systems is crucial. Although the issues impact Chromium and were fixed by the open-source project two weeks ago, Grafana received a bug bounty submission from security researcher Alex Chapman proving their exploitability in the Grafana components. Grafana Labs says that Grafana Cloud and Azure Managed Grafana instances have been patched, so users relying on externally hosted instances don't have to take any action. Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 03 Jul 2025 16:20:14 +0000