<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution]]></title><description><![CDATA[<p dir="auto">Researchers have pulled back the curtain on a stealthy Chromium-based post-exploitation framework dubbed <strong>PEEP</strong>, which disguises itself as a benign bookmarks extension to maintain persistence inside Chrome and Edge browsers.</p>
<p dir="auto">The toolkit is not a foothold itself—it demands pre-existing administrative privileges or code execution on the target host. Once that access is secured, its installer sidesteps the normal Web Store review process and any user consent prompts by injecting the extension directly into browser profiles. What makes this particularly nasty is how it forges Chromium’s own <em>Secure Preferences</em> file, effectively tricking the browser into treating the malicious add-on as both trusted and user-approved.</p>
<p dir="auto">That means PEEP can survive browser restarts and operate quietly under the radar, giving attackers a reliable channel to issue commands on the compromised machine through the browser itself.</p>
<p dir="auto">Key technical takeaways:</p>
<ul>
<li><strong>PEEP</strong> requires <strong>prior administrative or code execution access</strong>—it is not a remote code execution exploit.</li>
<li>It targets <strong>Chrome</strong> and <strong>Edge</strong> by modifying profile directories directly.</li>
<li>The installation bypasses <strong>Web Store checks</strong> and user prompts by forging <strong>Secure Preferences</strong>.</li>
<li>The extension’s purpose is <strong>post-compromise persistence</strong> and host-level command execution.</li>
</ul>
<p dir="auto">This isn’t a vulnerability in the browsers themselves—it’s an abuse of trust mechanisms that assumes the attacker already owns the box. Defenders should focus on monitoring abnormal modifications to browser profile directories and auditing extensions that appear without a corresponding Web Store installation event.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your organization taken steps to audit browser profiles for unauthorized extension injections, or do you rely on endpoint detection alone to catch this kind of post-exploitation movement?</p>
]]></description><link>https://xploitlk.com/topic/254/peep-turns-chrome-and-edge-into-post-compromise-backdoors-for-host-command-execution</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:12:08 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/254.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 07 Sep 2026 22:30:27 GMT</pubDate><ttl>60</ttl></channel></rss>