SECURITY·중요도 8·2026. 09. 07.·The Hacker News
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
── KO ──────────────────
PEEP는 Chrome과 Edge를 위한 복잡한 포스트-악용 툴킷이다.
PEEP는 Chrome과 Edge를 대상으로 한 복잡한 포스트-악용 툴킷으로, 웹 브라우저의 북마크 확장으로 위장한다. 이 툴킷은 사전 관리 권한이나 코드 실행 접근이 필요하며, 사용자의 프롬프트 없이 Chromium의 보안 기본 설정을 조작하여 확장을 프로필에 직접 주입한다.
── EN ──────────────────
PEEP is a complex post-exploitation toolkit for Chrome and Edge.
PEEP is a sophisticated post-exploitation toolkit targeting Chrome and Edge, masquerading as a bookmarks extension. It requires prior administrative or code execution access, injecting the extension directly into browser profiles while bypassing Store checks and user prompts by forging Chromium's Secure Preferences.