Validated Research Published: Aug 25, 2026

Computer-Use TOCTOU: The Agent Clicked a Screen It Had Not Rechecked

A computer-use agent selected a benign Continue button from a screenshot, paused to reason, and later clicked the same coordinates after the page had replaced that control with Outlook's Send button. The resulting email was written by the attacker. The case turns a familiar time-of-check to time-of-use race into a browser-agent problem: the observed screen cannot authorize a later action unless the target is revalidated immediately before the click.

Indirect Prompt InjectionHuman-in-the-LoopTool AuthorizationAgentic AIWeb Security
5 applicable AIDEFEND defenses
Source: TOCTOU Agent: What You Click Is Not What You Get 
Author: Johann Rehberger
Original article: Jun 25, 2026

Threat Analysis

  • The page first created a safe-looking target. It displayed a Continue button and embedded an indirect prompt asking the agent to calculate 1+1 through bash.
  • The harmless calculation was a timing primitive. It stretched Claude Computer Use's reasoning interval by about four to five seconds. During that gap, the agent retained the coordinates selected from its earlier screenshot.
  • The page changed what occupied those coordinates. It opened a prefilled Outlook compose view and aligned the Send button with the former Continue button. The email body and destination were already chosen by the attacker.
  • The agent acted on stale visual evidence. It did not re-observe the target immediately before dispatching the click. The old coordinate therefore sent the email, even though the action no longer matched the screen the model had reasoned about.
  • The issue predates this Claude reproduction. Jun Kokatsu originally reported the browser computer-use race against OpenAI Operator. Rehberger later reproduced the same failure class with Claude Computer Use and credited Kokatsu's discovery.
  • Anthropic addressed the race in a later product surface. Rehberger reports that Cowork added a pre-action check requiring the relevant pixels to remain unchanged. That mitigation is evidence for the control pattern, not proof that every computer-use implementation now enforces it.

Applicable AIDEFEND Defenses (5)

AID-I-008.002
Cross-Origin Read/Write Segmentation with Step-Up Confirmation
Very High
Immediately before a cross-origin browser write, re-observe the exact actionable element, origin, method, URL, and request. Revoke the decision if the element or surrounding pixels changed. This is the most specific control for the demonstrated replacement of Continue with Outlook Send.
AID-H-018.006
Continuous Authorization Verification (Anti-TOCTOU)
Very High
Bind the planned click to a canonical target and live preconditions, then re-check them at dispatch. A valid decision made from one screenshot must expire when navigation, focus, origin, element identity, or visible state changes during inference.
AID-H-018.003
High-Impact Independent Validation & Approval Gate
Very High
Sending email is an external state change. Require a fresh approval bound to the exact account, recipient, subject, body, and Send control. A generic instruction to continue browsing cannot authorize a message whose contents were supplied by the page.
AID-I-008.004
Desktop Computer-Use Workspace Isolation & Action Confirmation
High
Execute only against a stable accessibility element after consuming the exact approval receipt, then read back trusted UI or API evidence of the effect. This removes coordinate-only authority and gives the system a verifiable post-action result.
AID-H-019.002
Secure HTML Rendering & Content Demotion
Medium
Sanitize page content into bounded plain text and preserve its untrusted origin so a webpage cannot legitimately command an unrelated bash task. This weakens the attacker's timing setup, but it is only a supporting control because ordinary page changes can still create the same race.

What Defenders Should Do Now

  • Instrument computer-use actions with both an observation ID and an action-time observation. Fail closed if the origin, page, focus, element, geometry, or relevant pixels differ.
  • Prefer stable accessibility nodes or application APIs over raw coordinates. Bind the approved semantic action to the element identity and expected state.
  • Require exact confirmation for email, payment, account, permission, upload, and destructive actions. Show the final target and values after the last re-observation.
  • Test delayed swaps, navigation during inference, modal overlays, layout shifts, cross-origin embeds, and same-coordinate button replacement. Include delays created by tool calls as well as model reasoning.
  • Record the before image, action-time image, element identity, normalized action, approval receipt, and post-action result so reviewers can reconstruct what the agent saw and what it actually changed.

Conclusion

Computer-use systems introduce a physical timing gap between perception and action. A screenshot can support a plan, but it cannot remain the authority for a later click after the page has changed.

AIDEFEND  maps this failure to AID-I-008.002 and AID-H-018.006 at the action boundary, then adds AID-H-018.003 for the resulting high-impact write. These controls require the system to re-establish what is being clicked and what effect is being approved at the moment of use.