HackerFeeds

CyberSecurity News

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

The Hacker News
· September 7, 2026

AI summary

Researchers have revealed a post-exploitation toolkit called PEEP that targets Chromium-based browsers, disguising itself as a bookmarks extension. PEEP requires administrative or code execution access to install, and it injects the extension into Chrome and Edge profiles. This injection bypasses the usual Web Store checks and user prompts by mimicking Chromium's Secure Preferences. The toolkit enables host command execution, effectively turning the browsers into backdoors. PEEP's installation method allows it to operate without being detected by standard security measures. The toolkit's complexity and ability to evade detection make it a significant threat.

Read the full article at The Hacker Newsthehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.