Research · curated 27 Jun 2026
Computer-Use and TOCTOU: What You Click Is Not What You Get!
First reported embracethered.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Race-condition/TOCTOU flaws in computer-use agents let attackers manipulate what an autonomous agent actually clicks or acts upon, enabling unintended and potentially malicious actions.
The author reproduces a previously disclosed TOCTOU race-condition vulnerability against ChatGPT Operator, a computer-use AI agent, demonstrating that what the agent clicks is not what the user expects. A video demo of the attack was presented at the Real-world AI security conference.