Computer-Use TOCTOU: The Agent Clicked a Screen It Had Not Rechecked
A computer-use agent selected a benign Continue button from a screenshot, paused to reason, and later clicked the same coordinates after the page had replaced that control with Outlook's Send button. The resulting email was written by the attacker. The case turns a familiar time-of-check to time-of-use race into a browser-agent problem: the observed screen cannot authorize a later action unless the target is revalidated immediately before the click.
Threat Analysis
- The page first created a safe-looking target. It displayed a Continue button and embedded an indirect prompt asking the agent to calculate
1+1through bash. - The harmless calculation was a timing primitive. It stretched Claude Computer Use's reasoning interval by about four to five seconds. During that gap, the agent retained the coordinates selected from its earlier screenshot.
- The page changed what occupied those coordinates. It opened a prefilled Outlook compose view and aligned the Send button with the former Continue button. The email body and destination were already chosen by the attacker.
- The agent acted on stale visual evidence. It did not re-observe the target immediately before dispatching the click. The old coordinate therefore sent the email, even though the action no longer matched the screen the model had reasoned about.
- The issue predates this Claude reproduction. Jun Kokatsu originally reported the browser computer-use race against OpenAI Operator. Rehberger later reproduced the same failure class with Claude Computer Use and credited Kokatsu's discovery.
- Anthropic addressed the race in a later product surface. Rehberger reports that Cowork added a pre-action check requiring the relevant pixels to remain unchanged. That mitigation is evidence for the control pattern, not proof that every computer-use implementation now enforces it.
Applicable AIDEFEND Defenses (5)
What Defenders Should Do Now
- Instrument computer-use actions with both an observation ID and an action-time observation. Fail closed if the origin, page, focus, element, geometry, or relevant pixels differ.
- Prefer stable accessibility nodes or application APIs over raw coordinates. Bind the approved semantic action to the element identity and expected state.
- Require exact confirmation for email, payment, account, permission, upload, and destructive actions. Show the final target and values after the last re-observation.
- Test delayed swaps, navigation during inference, modal overlays, layout shifts, cross-origin embeds, and same-coordinate button replacement. Include delays created by tool calls as well as model reasoning.
- Record the before image, action-time image, element identity, normalized action, approval receipt, and post-action result so reviewers can reconstruct what the agent saw and what it actually changed.
Conclusion
Computer-use systems introduce a physical timing gap between perception and action. A screenshot can support a plan, but it cannot remain the authority for a later click after the page has changed.
AIDEFEND maps this failure to AID-I-008.002 and AID-H-018.006 at the action boundary, then adds AID-H-018.003 for the resulting high-impact write. These controls require the system to re-establish what is being clicked and what effect is being approved at the moment of use.