Bottom line: PEEP poses a significant risk to organizations with administrative access to Chrome/Edge.
What's happening: Researchers from Google's Project Zero have identified PEEP, which was linked to multiple attacks in the United States, United Kingdom, and China, and has a CVSS score of 9.8. The toolkit was first discovered in August 2022, and has since been linked to attacks in at least 20 countries.
What to do: Security leaders should immediately review their Chrome/Edge extensions and remove any suspicious bookmarks or extensions, and consider implementing additional security measures to prevent PEEP from being installed on their networks.