Return to Threats

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

thehackernews.com 2026-09-07 AI supply chain High

What Happened

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

Why It Matters

The article reports on PEEP, a post-exploitation toolkit that disguises itself as a Chromium bookmarks extension and is injected directly into Chrome/Edge profiles once an attacker already has administrative or code execution access, bypassing Web Store checks and user prompts by forging Secure Preferences. This turns widely used browsers into post-compromise backdoors for host command execution. From a RealGround perspective, browser extensions and underlying browser profiles are part of the broader application and AI supply chain: compromised extensions on endpoints used to interact with AI systems can be leveraged to hijack authenticated sessions, exfiltrate data, or modify inputs/outputs to AI agents. Organizations should treat browser and extension integrity as a critical supply-chain surface, inventory and monitor extensions on AI operator endpoints, and integrate browser security posture into SBOM and AI supply-chain risk assessments.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html

Talk to AI CISO