# Synthetics Recorder 1.4.15 Security Update (ESA-2026-16) - CVE-2025-6554 and CVE-2025-7657

**URL:** https://discuss.elastic.co/t/synthetics-recorder-1-4-15-security-update-esa-2026-16-cve-2025-6554-and-cve-2025-7657/385252
**Category:** Security Announcements
**Created:** [February 26, 2026, 4:55pm UTC](https://discuss.elastic.co/t/synthetics-recorder-1-4-15-security-update-esa-2026-16-cve-2025-6554-and-cve-2025-7657/385252 "2026-02-26T16:55:04Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![ismisepaul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismisepaul/32/102235_2.png) [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)
#### Post date: [February 26, 2026, 4:55pm UTC](https://discuss.elastic.co/t/synthetics-recorder-1-4-15-security-update-esa-2026-16-cve-2025-6554-and-cve-2025-7657/385252/1 "2026-02-26T16:55:04Z")

</div>

**Dependency on Vulnerable Third-Party Component in Synthetics Recorder Leading to Remote Code Execution**

Dependency on Vulnerable Third-Party Component (CWE-1395) exists in the bundled Chromium browser in Elastic Synthetics Recorder that could allow an attacker to achieve remote code execution on a user's system. Exploitation requires a user to navigate the Synthetics Recorder's built-in browser to a malicious or compromised website, which serves specially crafted, malformed content that triggers known vulnerabilities - CVE-2025-6554 and CVE-2025-7657.

**Affected Versions:**

All versions before 1.4.14

**Solutions and Mitigations:**

The issue is resolved in version 1.4.15.

**Severity:** CVSSv3.1: High ( 7.5 ) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H  
**CVE ID** : CVE-2025-6554 and CVE-2025-7657
