Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
chrome
1 Posts 1 Posters 5 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Researchers have pulled back the curtain on a stealthy Chromium-based post-exploitation framework dubbed PEEP, which disguises itself as a benign bookmarks extension to maintain persistence inside Chrome and Edge browsers.

    The toolkit is not a foothold itself—it demands pre-existing administrative privileges or code execution on the target host. Once that access is secured, its installer sidesteps the normal Web Store review process and any user consent prompts by injecting the extension directly into browser profiles. What makes this particularly nasty is how it forges Chromium’s own Secure Preferences file, effectively tricking the browser into treating the malicious add-on as both trusted and user-approved.

    That means PEEP can survive browser restarts and operate quietly under the radar, giving attackers a reliable channel to issue commands on the compromised machine through the browser itself.

    Key technical takeaways:

    • PEEP requires prior administrative or code execution access—it is not a remote code execution exploit.
    • It targets Chrome and Edge by modifying profile directories directly.
    • The installation bypasses Web Store checks and user prompts by forging Secure Preferences.
    • The extension’s purpose is post-compromise persistence and host-level command execution.

    This isn’t a vulnerability in the browsers themselves—it’s an abuse of trust mechanisms that assumes the attacker already owns the box. Defenders should focus on monitoring abnormal modifications to browser profile directories and auditing extensions that appear without a corresponding Web Store installation event.

    Source: The Hacker News

    Has your organization taken steps to audit browser profiles for unauthorized extension injections, or do you rely on endpoint detection alone to catch this kind of post-exploitation movement?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World