Vulnerable Chrome Running with Extension Install (CVE-2026-0628/GlicJack)
Detects the execution of a Google Chrome process on a system with a known vulnerability (versions below 143.0.7499.192) in conjunction with browser extension installation or loading activity. This behavior is indicative of the GlicJack exploit (CVE-2026-0628), where a malicious extension attempts to impersonate a trusted AI vendor server to send unauthorized commands to the in-browser AI agent.
YARA-L

