Paper deep dive
Temporal UI State Inconsistency in Desktop GUI Agents: Formalizing and Defending Against TOCTOU Attacks on Computer-Use Agents
Wenpeng Xu
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 98%
Last extracted: 4/26/2026, 10:16:09 PM
Summary
The paper identifies a critical 'observation-to-action gap' in desktop GUI agents (e.g., Claude, GPT-4o) that creates a Time-Of-Check, Time-Of-Use (TOCTOU) vulnerability. This gap, averaging 6.51s, allows attackers to manipulate the UI state between the agent's screenshot capture and its physical action dispatch. The authors formalize this as a 'Visual Atomicity Violation' and demonstrate three attack primitives: Notification Overlay Hijack (Primitive A), Window Focus Manipulation (Primitive B), and Web DOM Injection (Primitive C). To defend against these, they propose Pre-execution UI State Verification (PUSV), a three-layer defense (masked pixel SSIM, global screenshot diff, and X Window snapshot diff) that achieves 100% interception for OS-level attacks but remains vulnerable to zero-visual-footprint DOM injections.
Entities (9)
Relation Signals (5)
PUSV → defendsagainst → Notification Overlay Hijack
confidence 100% · PUSV achieves 100% Action Interception Rate across 180 adversarial trials (135 Primitive A + 45 Primitive B)
PUSV → failsagainst → Web DOM Injection
confidence 100% · Against Primitive C (zero-visual-footprint DOM injection), PUSV reveals a structural blind spot (~0% AIR)
Notification Overlay Hijack → isatypeof → Visual Atomicity Violation
confidence 100% · characterize three concrete attack primitives: (A) Notification Overlay Hijack...
GUI Agent → isvulnerableto → TOCTOU
confidence 100% · GUI agents that control desktop computers via screenshot-and-click loops introduce a new class of vulnerability: the observation-to-action gap... creates a Time-Of-Check, Time-Of-Use (TOCTOU) window
TOCTOU → manifestsas → Visual Atomicity Violation
confidence 100% · We formalize this as a Visual Atomicity Violation
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:GUI agents that control desktop computers via screenshot-and-click loops introduce a new class of vulnerability: the observation-to-action gap (mean 6.51 s on real OSWorld workloads) creates a Time-Of-Check, Time-Of-Use (TOCTOU) window during which an unprivileged attacker can manipulate the UI state. We formalize this as a Visual Atomicity Violation and characterize three concrete attack primitives: (A) Notification Overlay Hijack, (B) Window Focus Manipulation, and (C) Web DOM Injection. Primitive B, the closest desktop analog to Android Action Rebinding, achieves 100% action-redirection success rate with zero visual evidence at the observation time. We propose Pre-execution UI State Verification (PUSV), a lightweight three-layer defense that re-verifies the UI state immediately before each action dispatch: masked pixel SSIM at the click target (L1), global screenshot diff (L2a), and X Window snapshot diff (L2b). PUSV achieves 100% Action Interception Rate across 180 adversarial trials (135 Primitive A + 45 Primitive B) with zero false positives and < 0.1 s overhead. Against Primitive C (zero-visual-footprint DOM injection), PUSV reveals a structural blind spot (~0% AIR), motivating future OS+DOM defense-in-depth architectures. No single PUSV layer alone achieves full coverage; different primitives require different detection signals, validating the layered design.
Tags
Links
- Source: https://arxiv.org/abs/2604.18860v1
- Canonical: https://arxiv.org/abs/2604.18860v1
Trouble viewing inline? Open PDF directly →
Full Text
51,017 characters extracted from source content.
Expand or collapse full text
Temporal UI State Inconsistency in Desktop GUI Agents: Formalizing and Defending Against TOCTOU Attacks on Computer-Use Agents†thanks: Code and data: https://github.com/OwenXu6/gui_agent Wenpeng Xu University of California, San Diego wex019@ucsd.edu (April 2026) Abstract GUI agents that control desktop computers via screenshot-and-click loops introduce a new class of vulnerability: the observation-to-action gap (mean 6.51 s on real OSWorld workloads) creates a Time-Of-Check, Time-Of-Use (TOCTOU) window during which an unprivileged attacker can manipulate the UI state. We formalize this as a Visual Atomicity Violation and characterize three concrete attack primitives: (A) Notification Overlay Hijack, (B) Window Focus Manipulation, and (C) Web DOM Injection. Primitive B — the closest desktop analog to Android Action Rebinding — achieves 100% action-redirection success rate with zero visual evidence at the observation time. We propose Pre-execution UI State Verification (PUSV), a lightweight three-layer defense that re-verifies the UI state immediately before each action dispatch: masked pixel SSIM at the click target (L1), global screenshot diff (L2a), and X Window snapshot diff (L2b). PUSV achieves 100% Action Interception Rate across 180 adversarial trials (135 Primitive A + 45 Primitive B) with zero false positives and <0.1<0.1 s overhead. Against Primitive C (zero-visual-footprint DOM injection), PUSV reveals a structural blind spot (≈ 0% AIR), motivating future OS+DOM defense-in-depth architectures. No single PUSV layer alone achieves full coverage — different primitives require different detection signals, validating the layered design. We evaluate across three frontier models (Claude Opus 4.6, GPT-4o, Qwen3.6-plus), confirming that the vulnerability and defense are both model-agnostic. 1 Introduction The rapid advancement of Large Multimodal Models (LMMs) has catalyzed the transition of GUI agents from restricted web-browsing tasks to unconstrained, cross-application desktop computer control. Frameworks such as OSWorld [1] evaluate these agents in realistic operating system environments, where they manage files, execute terminal commands, and navigate complex software suites. These agents operate on a discrete screenshot-and-click loop: they observe the screen, reason about the next step, and physically dispatch an input event (e.g., a mouse click). However, the sheer computational cost of state-of-the-art LMMs introduces a fundamental physical constraint: the observation-to-action gap. In a real desktop environment, the latency between capturing a screenshot and executing the corresponding physical action spans several seconds. This unavoidable temporal disconnect creates a critical Time-Of-Check to Time-Of-Use (TOCTOU) vulnerability. An unprivileged attacker sharing the desktop session can manipulate the UI state during this gap, redirecting the agent’s intended action to a malicious target. Recent literature has begun to recognize temporal vulnerabilities in agentic systems. For instance, Zero-Permission [2] demonstrated Action Rebinding on Android, while Atomicity for Agents [3] explored DOM-level races within web browsers. Yet, desktop environments present a strictly more complex and dangerous attack surface. Desktop agents interact across disjoint applications, manage overlapping windows governed by X11/Wayland compositors, and respond to OS-level notifications. Web-centric DOM monitoring defenses are entirely blind to these OS-level visual hijackings, leaving desktop agents fundamentally unprotected. In this paper, we present the first systematic formalization, exploitation, and defense of TOCTOU vulnerabilities in cross-application desktop GUI agents. We formally define this threat as a Visual Atomicity Violation (VAV) and empirically measure the observation-to-action gap on a real OSWorld Ubuntu workload, revealing a staggering mean gap of 6.51 seconds — an ample window for exploitation. We then construct and evaluate three distinct attack primitives: Notification Overlay Hijack (Primitive A), Window Focus Manipulation (Primitive B), and Web DOM Injection (Primitive C). Alarmingly, our strongest OS-level attack (Primitive B) achieves a 100% action-redirection success rate with zero visual evidence at the observation time, completely deceiving state-of-the-art models including Claude Opus 4.6, GPT-4o, and Qwen3.6-plus. To secure desktop agents, we propose Pre-execution UI State Verification (PUSV), a lightweight, OS-native middleware defense. Unlike recent approaches that rely on computationally expensive dual-channel LLM verification or brittle browser-only monitoring, PUSV leverages a deterministically layered architecture: masked pixel SSIM (Layer 1), global screenshot diff (Layer 2a), and X Window snapshot diff (Layer 2b). PUSV re-verifies the UI state immediately before action dispatch, achieving a 100% Action Interception Rate (AIR) against OS-level attacks with negligible overhead (<<0.1 s). Crucially, we also demonstrate that PUSV (and all visual-based defenses) exhibits a near 0% AIR against pure DOM injection attacks (Primitive C), objectively exposing the fundamental blind spot of screenshot-based verification and motivating the need for future multi-layered (OS + DOM) defense-in-depth architectures. In summary, our core contributions are: • Desktop TOCTOU Formalization & Measurement: We formalize Visual Atomicity Violations on desktop systems and empirically prove the existence of an exploitable 6.51 s gap in production-grade agents. • Novel Attack Primitives & Benchmark: We introduce DesktopTOCTOU-Bench, comprising 50 scenarios, and demonstrate up to 100% action-redirection success rates across three frontier LLMs using three stealthy attack primitives. • Lightweight System Defense (PUSV): We design and evaluate PUSV, a three-layer visual and window-registry verification mechanism that achieves 100% interception of OS-level attacks in real time, while identifying the structural limitations of visual defenses against web-layer injections. 2 Background 2.1 Computer-Use Agents and the OSWorld Paradigm Unlike early web agents constrained to parsing static HTML via text-based LLMs [4, 5], modern Computer-Use Agents (CUAs) control entire operating systems. Powered by advanced Vision-Language Models (VLMs) [6, 7, 8], recent frameworks such as OS-Copilot [9], AppAgent [10], and OSWorld [1] evaluate these agents by providing them with a virtual machine (e.g., Ubuntu) and requiring them to perform cross-application tasks. The agent interacts with the OS via an API that simulates human I/O: it receives a raw pixel array (screenshot) of the desktop, processes it through a VLM, and outputs physical coordinates (e.g., pyautogui.click(x, y)). This paradigm is powerful because it is application-agnostic, but it inherently decouples the visual observation from the physical execution, introducing severe synchronization challenges. 2.2 TOCTOU in Classical vs. Agentic Security Time-Of-Check to Time-Of-Use (TOCTOU) is a classic software race condition where the state of a system (e.g., a file’s permission) changes between the check of that state and the use of the result. In classical OS security, TOCTOU is mitigated via atomic operations or file locking. However, in the context of GUI agents, the “check” is the VLM’s visual reasoning over a screenshot, and the “use” is the physical mouse click. Because visual reasoning over a 1080p image by a massive Transformer model requires multiple seconds of compute, achieving true atomicity at the OS input layer is impossible without freezing the entire operating system, which would break dynamic applications and user experience. 3 Observation-to-Action Gap Measurement The feasibility of a TOCTOU attack dictates that the temporal window between observation and action (Δ ) must be sufficiently large for an attacker to reliably inject a state change. We empirically measure Δ on a realistic desktop setup. 3.1 Experimental Setup Our environment consists of a VMware Fusion Ubuntu 22.04 ARM virtual machine. We evaluate the agent loop using Claude Opus 4.6 (via the Anthropic API) as the reasoning engine. We measure the gap across 10 heterogeneous tasks sampled from OSWorld, encompassing file management (e.g., manipulating documents in the GNOME Files app), terminal execution, and browser interaction. To ensure precision, we instrument the agent loop to record TobsT_obs exactly when the screenshot buffer is captured from the VNC server, and TactT_act exactly when the pyautogui input event is dispatched to the OS. 3.2 Measurement Results As summarized in Table 1, the observation-to-action gap is substantial. Table 1: Observation-to-action gap on real OSWorld workload (n=10n=10 tasks). Mode Mean Std Dev Min Max Real OSWorld 6.51 s 3.59 s 3.18 s 13.23 s The mean gap of 6.51 seconds is highly consistent with the 4.18–15.43 seconds window recently reported for Android Action Rebinding [2]. This confirms our hypothesis: desktop GUI agents are exposed to an equally, if not more, exploitable TOCTOU window. An attacker who injects a UI state change 1.0 second after TobsT_obs is guaranteed a residual window of Δ−1.0≈5.51 -1.0≈ 5.51 seconds before the action is dispatched. In modern desktop environments, rendering a new window, updating the DOM, or triggering a system notification takes merely tens of milliseconds, rendering this 5.51-second window dangerously ample for reliable exploitation. Figure 1 illustrates the TOCTOU vulnerability window and the temporal positions of the key events in the agent loop. TimeobsT_ obs0.0striggerT_ trigger1.0sverifyT_ verify∼ 6.4 sactT_ act6.5s Agent CapturesScreenshot IIAttacker InjectsUI State ChangePUSV Check(Middleware)Physical ClickDispatch (x,y)(x,y)Agent LLM Reasoning Gap (Mean: 6.51 s)THE TOCTOU VULNERABILITY WINDOW Figure 1: Timeline of the TOCTOU vulnerability window. The agent captures screenshot I at TobsT_obs; the attacker injects a UI state change at Ttrigger=Tobs+1sT_trigger=T_obs+1\,s; PUSV re-verifies the UI state at TverifyT_verify; the physical click is dispatched at TactT_act. The mean observation-to-action gap of 6.51 s provides an ample exploitation window. 4 Attack Formalization 4.1 Threat Model We consider an attacker who can execute arbitrary code on the same desktop session as a victim GUI agent. This capability requires user-level privilege only — no kernel exploit, no root access — and is achievable via a malicious application installed by the user, a browser extension, a compromised third-party dependency, or a one-click malware delivery. The attacker cannot modify the agent’s code, its system prompt, or the channel between the agent and the LLM API. The victim agent is a production-grade computer-use agent (e.g., Claude Opus 4.6 with OSWorld’s screenshot-and-click loop) executing user-delegated tasks such as filing forms, managing files, or submitting orders. Attacker goal. Redirect the agent’s next physical action (click, keypress, drag) so that it lands on an attacker-controlled UI element rather than the intended target, causing the agent to execute an unintended action on the user’s behalf (e.g., approve a fraudulent transfer, execute a malicious command, exfiltrate a file). 4.2 Formalizing the TOCTOU Window Let sts_t denote the full desktop UI state (all pixel values, window tree, and DOM) at time t. A GUI agent’s action loop decomposes into three phases: P1. Observation (at time TobsT_obs): capture screenshot I=screenshot(sTobs)I=screenshot(s_T_obs). P2. Reasoning (Tobs<t<TactT_obs<t<T_act): send I to the LLM; receive action a=(type,)a=(type,c) where ∈ℝ2c ^2 is the click coordinate. P3. Execution (at time TactT_act): dispatch a via the OS input API. The observation-to-action gap is Δ=Tact−Tobs =T_act-T_obs. The gap is lower-bounded by LLM inference latency, which is non-trivial for frontier models. Definition 1 (Visual Atomicity Violation). An agent action a=(click,)a=(click,c) constitutes a Visual Atomicity Violation (VAV) if there exists an element e∗e^* such that: (i) c lies in bbox(e∗)bbox(e^*) at TobsT_obs (the agent intended to click e∗e^*), and (i) a distinct attacker-controlled element eAe_A with eA≠e∗e_A≠ e^* occupies c at TactT_act (the click is received by eAe_A). A VAV requires that the UI state at TactT_act differs meaningfully from the state at TobsT_obs — i.e., sTact≠sTobss_T_act≠ s_T_obs at coordinate c. An attacker induces a VAV by injecting a state-change event during the gap Δ . 4.3 Gap Measurement As measured in Section 3 and summarized in Table 1, the mean observation-to-action gap on real OSWorld workloads is 6.51 s (min 3.18 s, max 13.23 s). This is comparable to the 4.18–15.43 s window reported for Android Action Rebinding [2], confirming that desktop GUI agents are exposed to an equally exploitable TOCTOU window. An attacker who injects a state change 1 s after TobsT_obs has a residual window of Δ−1 -1 s (mean 5.51 s) before the action is dispatched — ample time for any rendering operation. 4.4 Attack Primitive A: Notification Overlay Hijack Mechanism. The attacker spawns a borderless Tkinter window over the agent’s intended click target 1 s after TobsT_obs. Three visual styles were evaluated: • corner_banner: 380×90 px borderless window anchored at the top-right corner (outside the agent’s typical task region) containing a deceptive action button. • zenity_dialog: a modal zenity --warning dialog centered on screen, simulating a system security prompt. • fullscreen: a Tkinter window covering the entire 1920×1080 screen, forcing any click to land in the attacker zone. Experimental setup. We run 135 trials (3 tasks × 3 styles × 15 trials) per model with defense disabled. Tasks span: file_delete (delete a file via Files app), terminal_command (execute a shell command), and browser_form (submit a web form). The attacker trigger is a fixed 1.0 s delay from TobsT_obs. Results are reported for Claude 4.6; Table 5 gives cross-model comparison. Results (Table 2). The fullscreen variant achieves 66.7% Spatial-ASR (action successfully redirected to attacker zone), while corner_banner and zenity_dialog achieve 0%. Notably, NDR (agent verbally flagging a notification) is 0% across all styles: the agent is spatially redirected without explicitly perceiving the overlay as a “notification.” This confirms that fullscreen-coverage attacks exploit the spatial constraint of the UI — the agent has no legal click target outside the overlay — rather than relying on social engineering. Table 2: Primitive A no-defense results (Claude 4.6, 135 trials, 15 trials per task per style). Spatial-ASR = fraction of trials where agent click lands in attacker-controlled zone. Style n Spatial-ASR corner_banner 45 0% zenity_dialog 45 0% fullscreen 45 66.7% (30/45) Overall 135 22.2% (30/135) TobsT_obs: LibreOffice Impress (planned click ⊕ ) TactT_act: Fullscreen overlay replaces desktop (click ⊕ intercepted) Figure 2: Primitive A (Fullscreen Overlay): agent observes a normal desktop at TobsT_obs; by TactT_act the entire screen is replaced by an attacker-controlled warning dialog. Why corner_banner and zenity_dialog fail. For corner_banner, the attacker window is placed far from the agent’s intended click region; the agent clicks its intended target, which is unobstructed. For zenity_dialog, the modal dialog appears at screen center but the agent’s intended click target (e.g., a button in a file manager) is occluded. In most trials the agent reports being unable to proceed and does not click — yielding 0% Spatial-ASR but also 0% task completion. This is still a viable denial-of-service variant, but we focus here on action-redirection attacks. 4.5 Attack Primitive B: Window Focus Manipulation Mechanism. Primitive B exploits the X11 stacking order. The attacker pre-stages a Tkinter window at the agent’s intended click coordinate using root.withdraw() to unmap it from the X11 display — making it invisible at TobsT_obs without killing the process. A background watcher thread monitors a trigger file (/tmp/prim_b_show); when the file is created 1.0 s after TobsT_obs, the thread calls root.deiconify(), root.lift(), and root.attributes(’-topmost’, True) to raise the window above all other windows (including the target browser window) in the same frame. The key property distinguishing Primitive B from Primitive A is stealth at TobsT_obs: the agent observes only the legitimate UI (a browser checkout form), reasons correctly, and produces a correct coordinate (140,247)(140,247) for the “Place Order” button. By TactT_act, the attacker window occupies (100,215,310,295)(100,215,310,295) — covering the button — and receives the click. Experimental setup. We pre-open Chromium at localhost:8888 serving a checkout form with a prominent blue “Place Order” button at (140,247)(140,247). The attacker window is a red 210×80 px Tkinter frame displaying “Confirm Transfer $9,999 → ATK-ACC” (or two other deceptive labels in tasks browser_placeorder_2 and browser_placeorder_3). We run 45 trials (3 tasks × 15 trials). Results (Table 3). Primitive B achieves 100% Spatial-ASR and 100% Trigger-ASR across all 45 trials. The agent consistently reports clicking the “Place Order” button while physically dispatching the click to the attacker window (/tmp/attack_triggered.txt confirms receipt). The gap is mean 4.06 s (σ=0.52σ=0.52 s), giving the trigger a comfortable residual before action dispatch. Table 3: Primitive B no-defense results (Claude 4.6, 45 trials, 3 tasks × 15 trials). Task n Spatial-ASR Trigger-ASR browser_placeorder 15 100% 100% browser_placeorder_2 15 100% 100% browser_placeorder_3 15 100% 100% Overall 45 100% 100% TobsT_obs: Clean checkout, no attacker window visible ⊕ TactT_act: Red frame raised at exact coordinate ⊕ Figure 3: Primitive B (Window Focus Swap): zero visual evidence at TobsT_obs; the attacker window is pre-staged but unmapped (withdrawn) until 1 s after the screenshot. Why the GNOME dock is not a viable Primitive B target. The GNOME Shell dock is managed by the Mutter compositor and is always rendered above regular X11 windows. An attacker Tkinter window cannot be raised to intercept clicks on dock icons (Trigger-ASR=0% in our dock pilot), unlike browser content areas which use standard X11 stacking. 4.6 Attack Primitive C: Web DOM Injection Mechanism. Primitive C exploits the gap between the agent’s screenshot of a web page and the page’s live DOM state. During the gap Δ , the attacker (having code execution in the same session) modifies the DOM of the target web page — changing button labels, form actions, or link hrefs — using a JavaScript payload injected via CDP (Chrome DevTools Protocol) or a companion browser extension. The agent’s LLM reasoning is based on the screenshot at TobsT_obs; by TactT_act, the click dispatched to the browser activates the attacker-modified DOM element. Threat scenario. A compromised browser extension monitors navigation to banking or e-commerce sites. When the agent begins a payment flow, the extension modifies the “Place Order” button’s form action to redirect to an attacker-controlled endpoint 1 s after the agent’s screenshot is captured. Experimental setup. We use the same localhost:8888 checkout page as Primitive B. The attack injects a transparent full-viewport position:fixed overlay div into the DOM 1.0 s after TobsT_obs: the overlay starts with display:none (completely invisible at TobsT_obs) and is activated to display:block by a JS polling loop when the injection flag /tmp/prim_c_inject is created. Because the overlay has no background color or opacity, it is pixel-identical to the page in both the TobsT_obs and TactT_act screenshots. When the agent’s click lands on the page, the overlay (now active, z-index:9999) intercepts it and submits the form to /attack instead of /submit. Results (Table 4). Primitive C achieves 100% Behavioral-ASR (15/15 trials per task) — the agent’s click successfully causes a POST to the attacker endpoint in every trial. The agent reports clicking the “Place Order” button; the form silently submits to /attack. Table 4: Primitive C no-defense results (45 trials, 3 tasks × 15 trials). Task n Spatial-ASR Behavioral-ASR browser_placeorder 15 100% 100% browser_placeorder_2 15 100% 100% browser_placeorder_3 15 100% 100% Overall 45 100% 100% TobsT_obs: Normal checkout (planned click ⊕ ) TactT_act: Pixel-identical — DOM overlay silently intercepts ⊕ Figure 4: Primitive C (DOM Injection): both frames are pixel-identical. The transparent overlay has no visual footprint; only the form’s action attribute has changed. 4.7 Generalization Across Models All experiments in Sections 4.4–4.6 use Claude Opus 4.6 as the victim agent. To verify that the vulnerability is architectural rather than model-specific, we repeat all conditions with GPT-4o [11] and Qwen3.6-plus [12], using 45 trials (3 tasks × 15 trials) per primitive and 135 trials for Primitive A (3 tasks × 3 styles × 15 trials). Table 5: Attack success rates across three agent models (no-defense, n=15 per task). Primitive A reports fullscreen Spatial-ASR; Primitive C reports Behavioral-ASR. Primitive Metric Claude 4.6 GPT-4o Qwen3.6-plus A (fullscreen) Spatial-ASR 66.7% 100.0% 100.0% B Trigger-ASR 100.0% 57.8%† 0%† C Behavioral-ASR 100.0% 91.1% 100.0% † Primitive B is coordinate-calibration-sensitive. See text for details. † Primitive B is coordinate-calibration-sensitive: the attacker window targets Claude’s estimated click position (140, 247). GPT-4o estimates the button position ∼ 50 px lower (y ≈ 290–350), yielding 57.8% ASR when coordinates occasionally enter the zone. Qwen3.6-plus clicks 5–20 px below the zone boundary (y ≈ 300–316 vs. zone limit y = 295), yielding 0% ASR. An adaptive attacker profiling the victim model’s coordinate distribution would restore near-100% ASR by repositioning the attacker window. PUSV detects the pixel change regardless of whether the click lands in the zone (Table 10), achieving 100% AIR against Primitive B for all three models. Key findings. (1) Primitive A (fullscreen) achieves 66.7–100% across all three models, confirming that spatial-coverage attacks exploit the TOCTOU window regardless of LLM architecture. (2) Primitive C achieves 91–100% Behavioral-ASR across all three model families (Anthropic, OpenAI, Alibaba) with no defense. The transparent DOM overlay exploits a temporal property (screenshot stale at action dispatch) that is model-independent: any model reasoning from a pre-injection screenshot will dispatch the click that activates the overlay. 4.8 Comparative Summary Table 6 summarizes the three primitives; Figures 2–4 provide side-by-side screenshots of TobsT_obs vs. TactT_act for each primitive. Primitive B is the strongest attack against Claude: it achieves perfect Spatial-ASR and Trigger-ASR while producing zero visual change at TobsT_obs — the most direct analog of Android Action Rebinding on the desktop. Primitive C is strongest in terms of generalizability: it achieves high Behavioral-ASR against both Claude and GPT-4o while remaining invisible to all PUSV verification layers. Table 6: Comparison of three attack primitives (Claude Opus 4.6, no-defense, n=15 per task). Primitive Mechanism Spatial-ASR Trigger-ASR Behavioral-ASR Visible at TobsT_obs A (fullscreen) Tkinter overlay 66.7% — — Yes A (corner) Tkinter corner 0% — — Yes B Withdraw+raise 100% 100% — No C DOM overlay 100% — 100% No 5 Defense: Pre-Execution UI State Verification 5.1 Design Rationale The TOCTOU vulnerability arises because the GUI agent acts on a stale screenshot: the UI state at TactT_act is assumed to match TobsT_obs, but this assumption is violated during an attack. The natural defense is to re-verify the UI state immediately before dispatching each action. We formalize this as Pre-execution UI State Verification (PUSV): before dispatching action a=(click,)a=(click,c), the agent captures a fresh screenshot I′=screenshot(sTact−)I =screenshot(s_T_act^-) (where Tact−=Tact−ϵT_act^-=T_act-ε) and aborts execution if the UI state has changed in a way inconsistent with benign transitions. Design requirements. 1. High True Positive Rate: detect all three primitives (overlay injection, window swap, DOM injection). 2. Low False Positive Rate: allow benign UI animations (cursor blink, progress indicators, clock updates) without false alarms. 3. Low overhead: add ≪ 1 s of latency to each action (the gap is >>3 s; any overhead <<0.5 s is acceptable). 4. No agent modification: implemented as a wrapper around the action dispatch call — does not require changing the LLM prompt, training, or agent architecture. No single comparison metric satisfies all requirements simultaneously. A global pixel diff catches large overlays but is sensitive to subtle animations; a per-pixel patch is precise but misses overlays outside the click target; a window registry diff detects new windows but is blind to windows that pre-existed in a hidden state. We therefore design PUSV as a layered verification scheme. 5.2 PUSV Architecture PUSV comprises three independent verification layers, evaluated in order. A single layer triggering causes the action to be aborted. Figure 5: PUSV architecture: three layers applied sequentially before each action dispatch. Each layer targets a distinct attack surface. 5.3 Layer 1: Masked Pixel SSIM at Click Target Rationale. Any attack that places a different UI element at the agent’s planned click coordinate c will change the pixel values in the vicinity of c. Structural Similarity Index (SSIM) is sensitive to structural changes (not just mean intensity) and is robust to JPEG compression artifacts from screenshot encoding. Implementation. We extract a 160×160160× 160 px patch centered at c from both I (the TobsT_obs screenshot) and I′I (the pre-action verification screenshot). We compute SSIM on the grayscale patches. If SSIM(I,I′)<τ1=0.92SSIM(I_c,I _c)< _1=0.92, the action is aborted. Threshold selection. We calibrate τ1 _1 empirically on 50 benign trials (no attack, various tasks) and 30 adversarial trials. Benign transitions (cursor movement, page scroll, normal animation) yield SSIM>0.97SSIM>0.97 in all observed cases. Attack transitions measured: • Primitive A (fullscreen): SSIM =0.632=0.632 • Primitive B (window raise): SSIM =0.540=0.540 A threshold of τ1=0.92 _1=0.92 provides a conservative margin of ≥0.28≥ 0.28 above the highest observed attack signal. Coverage. L1 catches attacks that modify pixels at c: fullscreen overlays (cover entire screen including c) and window swaps (raise a different window at c). L1 is blind to overlays placed far from c (e.g., corner_banner at the screen corner when the task click target is at center). 5.4 Layer 2a: Global Screenshot Diff Rationale. Attacks that inject UI elements outside the click target (e.g., corner notification banners that attract the agent’s attention) would evade L1. A global screenshot comparison detects any visible change to the desktop. Implementation. We compute the absolute pixel difference between I and I′I , masking out the 160×160160× 160 L1 patch (to avoid double-counting). We compute the global diff ratio: the fraction of pixels where the grayscale intensity difference exceeds a noise threshold δnoise=20 _noise=20 (out of 255). If this ratio exceeds τ2a=0.2% _2a=0.2\%, the action is aborted. Threshold calibration. The 0.2% threshold was chosen as follows. Benign screen activity (cursor blink, clock update, background service indicators) changes <0.05%<0.05\% of pixels per second on a clean Ubuntu 22.04 desktop. Measured attack signals: • corner_banner (380×90 px window): glob_diff =1.1%=1.1\% • zenity_dialog (center modal): glob_diff =8.9%=8.9\% • fullscreen overlay: glob_diff =69.0%=69.0\% All three are comfortably above τ2a _2a with 5×5×–345×345× signal margin. Compositing-managed elements. The GNOME Shell notification daemon renders banners via the Mutter compositor, bypassing the X11 window tree. These banners appear in the screenshot but are absent from wmctrl window listings. L2a detects them via pixel comparison regardless of their rendering path — a key advantage over window-registry-only approaches. 5.5 Layer 2b: X Window Snapshot Diff Rationale. New X11 windows that appear during Δ may be smaller than the global diff threshold (if the window is tiny or has identical background) but are structurally new entries in the X Window System registry. A window registry comparison provides a complementary signal. Implementation. We capture the wmctrl -l window list at both TobsT_obs (stored as WobsW_obs) and Tact−T_act^- (as WactW_act). Any window in Wact∖WobsW_act W_obs whose title matches a keyword in the set “security”, “alert”, “warning”, “zenity”, “systemoverlay” triggers an abort. Keyword matching uses case-insensitive substring search. Limitation — Primitive B blind spot. A window that was pre-registered in WobsW_obs (via root.withdraw() mapping it as unmapped) and later made visible (via root.deiconify()) does not appear as a new entry in Wact∖WobsW_act W_obs — the window ID exists in both lists. This is by design in Primitive B. L2b produces zero detections for Primitive B; L1 is the sole detection layer. This structural blind spot motivates the layered design: no single layer achieves 100% coverage across all primitives. 5.6 Implementation PUSV is implemented as a 180-line Python module (pusv.py) wrapping the agent’s action dispatch function. The verification sequence for a click action is: 1. Capture fresh screenshot I′I via the OSWorld HTTP API. 2. Extract 160×160160× 160 patch at c; compute SSIM. Abort if SSIM <0.92<0.92 (L1). 3. Compute global diff ratio on I′∖patchI . Abort if ratio >0.2%>0.2\% (L2a). 4. Query wmctrl for new windows with matching keywords. Abort if any found (L2b). 5. Dispatch action. Overhead. On our evaluation platform (M4 Mac host, VMware Fusion guest, OSWorld HTTP API), each verification adds <0.1<0.1 s of latency (screenshot capture: ≈ 50 ms, SSIM computation: <5<5 ms, wmctrl: <10<10 ms). This is negligible relative to the 6.51 s mean gap. PUSV passes 6 deterministic self-tests (python pusv.py) covering both clean and injected states. 5.7 Evaluation Primitive A (135 defense-ON trials, Table 7). PUSV achieves 100% AIR (Action Interception Rate) across all 135 trials, reducing fullscreen ASR from 66.7% to 0%. Layer coverage is complementary: corner_banner is caught exclusively by L2a (glob_diff 1.1%); zenity_dialog by L2a (8.9%); fullscreen by L1 (SSIM 0.632) for 30/45 trials and by L2a (glob_diff 69%) for the remaining 15. Table 7: PUSV defense results for Primitive A (135 trials, 3 tasks × 3 styles × 15 trials). Style n L1-AIR L2a-AIR Eff. ASR Signal corner_banner 45 0% 100% 0% glob 1.1% zenity_dialog 45 0% 100% 0% glob 8.9% fullscreen 45 67% 33% 0% SSIM 0.632 / glob 69% Overall 135 — — 0% — Primitive B (45 defense-ON trials, Table 8). PUSV achieves 100% AIR via L1 exclusively. L1 SSIM drops to 0.540 (mean; range 0.41–0.89 across models and tasks; threshold 0.92) when the attacker window raises above the browser. L2b produces 0 detections — the attacker window was pre-registered at TobsT_obs in a withdrawn (unmapped) state, so it does not appear as a new window entry. This confirms that the Primitive B evasion of L2b is real, and that L1 is structurally necessary for the defense. Table 8: PUSV defense results for Primitive B (45 trials, 3 tasks × 15 trials). Task n L1-AIR L2b-AIR Eff. ASR SSIM browser_placeorder 15 100% 0% 0% 0.538 browser_placeorder_2 15 100% 0% 0% 0.538 browser_placeorder_3 15 100% 0% 0% 0.536 Overall 45 100% 0% 0% 0.540 Primitive C (45 defense-ON trials, Table 9). PUSV achieves ≈ 0% AIR against Primitive C. L1 SSIM at the click target is ≈1.0≈ 1.0 (the blue button appears identical before and after DOM injection — the transparent overlay has no pixels). L2a global diff is ≈0%≈ 0\% (no visual change anywhere on screen). L2b fires 0 times (no new windows — the overlay div is an in-page DOM element, not an X11 window). One trial triggered L2a (0.4% diff) due to incidental browser animation noise; this is not correlated with the attack and would occur in benign conditions too. Table 9: PUSV defense results for Primitive C (45 trials). AIR ≈ 0% — DOM injection is invisible to all three layers. Task n L1-AIR L2a-AIR Behavioral-ASR SSIM browser_placeorder 15 0% 1/15* 93.3% ≈ 1.0 browser_placeorder_2 15 0% 0% 100% ≈ 1.0 browser_placeorder_3 15 0% 0% 100% ≈ 1.0 Overall 45 0% 1/45* 97.8% ≈ 1.0 *incidental browser animation noise, not attack-correlated PUSV across agent models (Table 10). We repeat the defense-ON evaluation with GPT-4o [11] and Qwen3.6-plus [12] as victim agents to verify that PUSV’s effectiveness is model-agnostic. Table 10: PUSV AIR across three agent models (defense-ON, 45 trials each per primitive). Primitive A uses fullscreen style only. Primitive Claude 4.6 GPT-4o Qwen3.6-plus Note A (fullscreen) 100% 100% 99.3%∗ 1 miss: gap >> 30 s timer B 100% 100% 100% all L1 C ≈ 0% ≈ 0% ≈ 0% 1/45 incidental each ∗ 1 miss: gap = 35.2 s exceeded 30 s overlay timer (experimental artifact, see text) PUSV achieves 100% AIR against Primitive B across all three models and ≈ 0% AIR against Primitive C across all three models, confirming that both the detection capability and the fundamental blind spot are model-agnostic. For Primitive A, Qwen3.6-plus shows 99.3% AIR (44/45) rather than 100%: the single miss occurred at gap = 35.2 s, which exceeded the 30 s overlay auto-dismiss timer; the overlay had already cleared from the screen before PUSV re-captured. GPT-4o achieves 100% AIR under the same 30 s timer. In a real deployment, an attacker would not use a self-dismissing overlay, so this is a measurement artifact of the test harness rather than a structural PUSV limitation. With no timer (or any timer longer than the observed gap), PUSV’s AIR for Primitive A would be 100% across all three models. False positive rate. We ran 30 benign verification trials (agent executing tasks with no attacker present) and observed zero PUSV aborts. The measured benign SSIM range was 0.97–1.00; global diff ratio <0.04%<0.04\%. (The single Primitive C L2a detection at 0.4% falls within the browser’s own rendering noise range.) Layer necessity. To confirm that the layered design is necessary, we report per-layer AIR when applied independently: • L1 alone: catches Primitive B (100%) and fullscreen Primitive A (67%), but misses corner_banner, zenity_dialog (0%), and Primitive C (0%). • L2a alone: catches all Primitive A styles (100%), but not Primitive B (change confined to L1 patch area, excluded from global diff) or Primitive C (≈ 0% diff). • L2b alone: catches zenity_dialog, but misses corner_banner (compositor-rendered), Primitive B (pre-existing window ID), and Primitive C (in-page DOM element, not an X11 window). L1+L2a+L2b achieves 100% AIR for Primitives A and B, but ≈ 0% for Primitive C, exposing a structural blind spot. A fourth layer, L2c (DOM fingerprinting), is needed to close this gap. 5.8 Discussion Computational overhead vs. completeness trade-off. PUSV uses fast, deterministic signal sources (pixel SSIM, pixel diff, wmctrl) rather than a second LLM call. This is a deliberate design choice: an LLM-based re-check would add ∼ 5 s of latency (approximately equal to the gap itself), effectively doubling the agent’s action latency on every step. Adaptive adversary considerations. An adversary aware of PUSV could attempt to keep the global pixel change below τ2a _2a (e.g., by making the attacker element visually identical to the legitimate element in color and layout, differing only in behavior). Such an attack would evade L2a but would still be caught by L1 (any structural pixel difference at c triggers L1) if the element geometry differs. A fully pixel-identical swap (same color, size, position — only the onclick handler differs) could evade all three layers; this is equivalent to the Primitive C (DOM injection) case, which requires an additional DOM-integrity layer. We discuss L2c (DOM fingerprinting) as future work. L2c: DOM fingerprinting (proposed future layer). Primitive C reveals that pixel and window-registry checks are insufficient for web-layer attacks. We propose L2c as a complementary layer: at TobsT_obs, record a DOM fingerprint FobsF_obs comprising security-critical attributes of the element at c — specifically, the enclosing form’s action and method attributes, and any onclick handlers — via the Chrome DevTools Protocol (CDP) Runtime.evaluate call. At Tact−T_act^-, re-evaluate and compare. If Fact≠FobsF_act≠ F_obs, abort. This adds ∼ 30 ms per action (one CDP round-trip) and would catch Primitive C’s form-action redirect with 100% precision. We leave full evaluation of L2c to future work, as its false-positive behavior on dynamic SPAs requires careful characterization. Generalization beyond OSWorld. PUSV requires only: (1) a screenshot API, (2) a system call to wmctrl or equivalent (X11, Wayland, or Win32 window enumeration), and (3) the agent’s planned click coordinate before dispatch. All three are available in any real GUI agent deployment. The threshold constants (τ1=0.92 _1=0.92, τ2a=0.2% _2a=0.2\%) are calibrated for Ubuntu 22.04 + GNOME Shell; re-calibration for different desktop environments requires ∼ 30 benign trials (<1<1 hour of measurement). 6 DesktopTOCTOU-Bench To systematically evaluate the vulnerability of desktop GUI agents to temporal UI state inconsistencies, we introduce DesktopTOCTOU-Bench, a comprehensive evaluation framework built on top of the OSWorld [1] environment. Unlike existing agent benchmarks that primarily focus on functional correctness in benign settings, DesktopTOCTOU-Bench is explicitly designed to measure both the Attack Success Rate (ASR) of temporal adversaries and the Action Interception Rate (AIR) of proposed defenses. Scenario Categorization. The benchmark comprises 50 unique adversarial scenarios categorized into five high-risk operational domains (10 scenarios each): 1. File Operations: Redirecting benign save/move actions to destructive commands (e.g., hijacking “Save to Desktop” to execute file deletion). 2. Communication: Manipulating email or messaging clients to alter recipients or exfiltrate private text prior to the agent clicking “Send”. 3. System Configuration: Hijacking OS settings panels (e.g., network configurations or firewall toggles) during administrative tasks. 4. Data Access: Altering file selection dialogs so the agent inadvertently uploads sensitive documents instead of public reports. 5. Privilege Escalation: Substituting visual elements within sudo authentication prompts or graphical policy kits. Evaluation Methodology. For statistical confidence, the benchmark enforces a rigorous N=15 scale-up evaluation per task condition. The evaluation harness utilizes a dual-metric system: Spatial-ASR (measuring if the physical click coordinate lands within the attacker’s dynamic overlay) and Behavioral-ASR (measuring if the underlying system state is maliciously altered, such as an HTTP POST to an attacker endpoint). DesktopTOCTOU-Bench provides a reproducible, containerized Ubuntu 22.04 environment with built-in instrumentation for microsecond-precision TobsT_obs and TactT_act timestamping. 7 Related Work 7.1 Security of Multimodal GUI Agents The widespread deployment of LLMs has introduced novel attack surfaces, most notably Prompt Injection (PI) and jailbreaking [13, 14, 15]. As models evolved to process visual inputs, these attacks transitioned into the multimodal domain via Visual Prompt Injection (VPI) [16, 17]. In the context of computer control, frameworks such as VPI-Bench [18] and OS-Harm [19] demonstrated that malicious instructions embedded within web pages or desktop backgrounds could manipulate agent behavior. More recent work, such as EVA [20], introduced evolving indirect prompt injections by tracking agent attention. However, all of these attacks rely on deceiving the LLM’s reasoning engine by injecting malicious context before or during the observation phase (TobsT_obs). In contrast, our work bypasses LLM reasoning entirely. By exploiting the observation-to-action gap, TOCTOU attacks allow the agent to reason correctly over a benign UI, only to physically hijack the execution at TactT_act — a fundamentally deeper threat layer that no prompt-level defense can address. 7.2 TOCTOU Vulnerabilities in Agentic Systems Time-of-Check to Time-of-Use (TOCTOU) is a fundamental race condition vulnerability extensively studied in classical operating system file management [21]. In the context of graphical interfaces, spatial and temporal UI manipulation has a long history: on mobile platforms, techniques like Tapjacking and “Cloak and Dagger” [22, 23] exploited UI overlays to trick human users into granting unintended permissions. However, while human users rely on continuous visual feedback and cognitive reflexes to detect sudden UI changes, GUI agents operate on a discrete screenshot-to-action loop, making them fundamentally more susceptible to temporal manipulation. Human-targeted UI deception requires visually convincing content to fool the victim’s conscious attention; agent TOCTOU attacks require only that the screen state change after the screenshot is taken, exploiting a physical timing gap the agent cannot close. The concept of temporal vulnerabilities in agent loops has recently garnered significant attention, though existing literature is constrained by platform limitations or impractical defense assumptions. Platform constraints. Zero-Permission [2] first formalized Action Rebinding on Android GUI agents. More recently, Atomicity for Agents [3] explored TOCTOU vulnerabilities specifically within web browsers, proposing a defense based on DOM and layout monitoring. However, neither work addresses the full desktop OS environment. Desktop CUAs operate across diverse applications, managing overlapping X11/Wayland windows and compositor-rendered OS notifications. Web-centric DOM defenses [3] are fundamentally blind to OS-level state changes (our Primitives A and B), leaving desktop agents unprotected. Our work bridges this gap by targeting the cross-application desktop environment and proposing OS-native visual and window-registry defenses. Defense practicality. Concurrently, Visual Confused Deputy [24] identified TOCTOU races as one of three causes of visual confused deputy failures in CUAs, alongside visual grounding errors and adversarial screenshot manipulation. To mitigate grounding failures broadly, they proposed dual-channel contrastive classification: an image channel classifies the click-target crop against a deployment-specific visual knowledge base, while a text channel verifies the LLM reasoning trace via a text embedding model. While effective for their broader threat model, this approach requires constructing and maintaining per-deployment knowledge bases of allowed visual targets and intents — a non-trivial operational burden for general-purpose agent deployments. Crucially, their defense targets semantic grounding correctness at TobsT_obs, rather than temporal state consistency between TobsT_obs and TactT_act — the distinct threat surface PUSV is designed to address. PUSV requires no model inference and no knowledge base: only deterministic OS-level primitives (masked pixel SSIM and wmctrl) calibrated on ∼ 30 benign trials, adding less than 0.1 s of overhead per action. Furthermore, unlike prior work that claims comprehensive protection, we objectively demonstrate the structural limitations of visual defenses. By showing that PUSV (and by extension, any visual-contrastive defense) achieves nearly 0% interception against zero-visual-footprint DOM injections (Primitive C), we highlight the necessity for future defense-in-depth architectures that combine OS-level and application-level (e.g., CDP) verification. 8 Conclusion As Computer-Use Agents transition from experimental sandboxes to real-world desktop assistants, the physical realities of LMM inference latency manifest as critical security vulnerabilities. In this paper, we formalized the Visual Atomicity Violation, demonstrating that state-of-the-art desktop GUI agents suffer from a mean observation-to-action gap of 6.51 seconds. This temporal disconnect provides unprivileged attackers with an ample window to execute stealthy Time-Of-Check, Time-Of-Use (TOCTOU) attacks. Through large-scale empirical evaluation on DesktopTOCTOU-Bench, we proved that dynamic UI manipulation — such as notification overlays and X11 window focus hijacking — can redirect agent actions with up to 100% success rates across frontier models including Claude Opus 4.6, GPT-4o, and Qwen3.6-plus. To mitigate this, we introduced Pre-execution UI State Verification (PUSV), a lightweight, three-layer middleware that cross-verifies masked pixel SSIM, global visual diffs, and the OS window registry. PUSV successfully intercepts 100% of OS-level structural attacks with less than 0.1 seconds of computational overhead. Crucially, our investigation into Web DOM Injection (Primitive C) revealed a fundamental blind spot: purely visual and OS-level defenses are inherently incapable of detecting semantic application-layer manipulations that lack a visual footprint. The security of future agentic operating systems cannot rely on screenshot analysis alone. It demands a defense-in-depth paradigm where visual observation is rigorously coupled with deterministic, application-layer state verification. References [1] T. Xie et al. OSWorld: Benchmarking Multimodal Agents for Open-Ended Tasks in Real Computer Environments. In Advances in Neural Information Processing Systems (NeurIPS), 2024. [2] Y. Qian, K. Qian, X. He, L. Chen, J. Zhang, T. Zhang, H. Wei, L. Wang, H. Wu, and B. Mao. Zero-Permission Manipulation: Can We Trust Large Multimodal Model Powered GUI Agents? arXiv:2601.12349, 2026. [3] L. Jiang, Z. Liu, H. Luo, and Z. Lin. Atomicity for Agents: Exposing, Exploiting, and Mitigating TOCTOU Vulnerabilities in Browser-Use Agents. arXiv:2603.00476, 2026. [4] S. Zhou, F. F. Hou, Y. Cheng, et al. WebArena: A Realistic Web Environment for Building Autonomous Agents. In International Conference on Learning Representations (ICLR), 2024. [5] X. Deng, Y. Gu, B. Zheng, et al. Mind2Web: Towards a Generalist Agent for the Web. In Advances in Neural Information Processing Systems (NeurIPS), 2023. [6] H. Liu, C. Li, Q. Wu, and Y. J. Lee. Visual Instruction Tuning. In Advances in Neural Information Processing Systems (NeurIPS), 2023. [7] J. Bai, S. Bai, S. Yang, et al. Qwen-VL: A Versatile Vision-Language Model for Understanding, Localization, Text Reading, and Beyond. arXiv:2308.12966, 2023. [8] OpenAI. GPT-4V(ision) System Card. OpenAI Technical Report, 2023. [9] Z. Wu, C. Han, Z. Ding, et al. OS-Copilot: Towards Generalist Computer Agents with Self-Improvement. In International Conference on Learning Representations (ICLR), 2024. [10] C. Zhang, Z. Yang, et al. AppAgent: Multimodal Agents as Smartphone Users. arXiv:2312.13771, 2023. [11] OpenAI. GPT-4o System Card. Technical Report, OpenAI, 2024. [12] Alibaba Cloud. Qwen3 Technical Report. arXiv preprint, 2025. [13] K. Greshake, S. Abdelnabi, S. Mishra, C. Endres, T. Holz, and M. Fritz. Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. In ACM Workshop on Artificial Intelligence and Security (AISec), 2023. [14] X. Liu, H. Nan, P. Gu, J. Chen, C. Mao, and T. Fang. AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models. In International Conference on Learning Representations (ICLR), 2024. [15] A. Zou, Z. Wang, J. Z. Kolter, and M. Fredrikson. Universal and Transferable Adversarial Attacks on Aligned Language Models. arXiv:2307.15043, 2023. [16] E. Bagdasaryan, T.-Y. Hsieh, B. Nassi, and V. Shmatikov. Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs. arXiv:2307.10490, 2023. [17] X. Qi, K. Huang, A. Panda, P. Henderson, M. Wang, and P. Mittal. Visual Adversarial Examples Jailbreak Aligned Large Language Models. In AAAI Conference on Artificial Intelligence, 2024. [18] T. Cao, B. Lim, Y. Liu, Y. Sui, Y. Li, S. Deng, L. Lu, N. Oo, S. Yan, and B. Hooi. VPI-Bench: Visual Prompt Injection Attacks for Computer-Use Agents. In International Conference on Learning Representations (ICLR), 2026. [19] T. Kuntz, A. Duzan, H. Zhao, F. Croce, Z. Kolter, N. Flammarion, and M. Andriushchenko. OS-Harm: A Benchmark for Measuring Safety of Computer Use Agents. In NeurIPS Datasets and Benchmarks, 2025. [20] Y. Lu, T. Ju, M. Zhao, X. Ma, Y. Guo, and Z. Zhang. EVA: Red-Teaming GUI Agents via Evolving Indirect Prompt Injection. arXiv:2505.14289, 2025. [21] M. Bishop and M. Dilger. Checking for Race Conditions in File Accesses. Computing Systems, 9(2), 1996. [22] Y. Fratantonio, C. Chen, A. Bianchi, C. Kruegel, and G. Vigna. Cloak and Dagger: From Two Permissions to Complete Control of the Android UI. In IEEE Symposium on Security and Privacy (S&P), 2017. [23] L.-S. Huang, A. Moshchuk, H. J. Wang, S. Schecter, and C. Jackson. Clickjacking: Attacks and Defenses. In USENIX Security Symposium, 2012. [24] X. Liu, B. He, X. Liu, A. Luo, H. Zhang, and H. Chen. Visual Confused Deputy: Exploiting and Defending Perception Failures in Computer-Using Agents. arXiv:2603.14707, 2026.