Cloud Browser: URL-policy rejection after Amazon navigation despite Always allow, with no actionable recovery
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
Summary
During an authorized public product-price comparison in ChatGPT Work, Cloud Browser could not continue after navigating to https://www.amazon.co.jp/. The browser tab reached an internal Chrome error page, and subsequent page inspection returned a Browser URL policy rejection. The user checked Cloud Browser settings: the default is Always allow, and the screenshot shows no site-specific deny entry.
Please clarify the scope of the denial and provide an actionable, supported recovery or escalation path. This report does not establish whether the underlying Amazon navigation failure is intentional blocking, a network failure, or a defect in handling an internal browser error page.
Environment and scope
- Observed September 12, 2026.
- ChatGPT Work's remote Cloud Browser, distinct from the user's own desktop Chrome.
- Cloud Browser settings inspected by the user in the iOS app.
- Public HTTPS destination; no credentials, checkout, or purchase was needed for the attempted lookup.
Observed sequence
- The task requests a public product comparison including Amazon Japan.
- The agent navigates its Cloud Browser tab to
https://www.amazon.co.jp/. - The tab reaches an internal Chrome error page rather than a usable Amazon page.
- Subsequent page inspection is rejected with the following message:
Browser Use rejected this action due to browser security policy.
Reason: The browser URL policy blocks this action.
Cloud browser cannot visit the requested page because its URL is blocked by the Cloud browser URL policy.
The agent must not attempt to achieve the same outcome via workaround, indirect execution, raw CDP or browser commands, alternate browser surfaces, or policy circumvention.
Proceed only with a materially safer alternative that does not require this blocked browser action; if none exists, stop and request user input.
- The user supplies a screenshot of Settings > Cloud Browser. It shows the default as Always allow, a site-permissions section with Add site, and no listed site-specific blocks.
- The agent's documented browser capabilities provide no URL-policy inspection, scoped re-evaluation, or permission-repair operation. The requested Amazon price/delivery comparison remains incomplete.
Important diagnostic limits
- The observed rejection does not by itself prove that the Amazon HTTPS destination is the policy's target. An internal error-page URL may be involved.
- We have not established the cause of the original navigation failure.
- There is no evidence that the user's own Chrome session is broken, that Amazon is generally unavailable, or that this affects every account.
- The user permission setting and the URL-policy rejection should not be treated as the same control without evidence.
- No policy bypass, proxy change, alternate browser route to the denied action, or security-setting modification was attempted as part of this report.
Expected behavior / requested investigation
- Identify whether the rejected URL is the requested public destination or the resulting internal error page.
- Explain which policy layer is responsible and whether this behavior is intentional.
- If a user setting can legitimately resolve it, expose the exact setting and a supported way to re-evaluate the denied action.
- If it cannot be resolved by the user or agent, provide an actionable error and a direct diagnostic-report path instead of repeatedly asking for approval that does not resolve the issue.
The official browser guide describes Cloud Browser website permissions, including Always allow and site overrides: https://learn.chatgpt.com/docs/browser#security-and-user-controls
Potentially related, but not an established shared cause: #41386 concerns an internal browser error page preventing later browser operations on the desktop in-app browser. This report concerns the remote Cloud Browser after a public HTTPS navigation.
Only the public destination, minimal settings description, and the error text are included. No account details, cookies, credentials, screenshots, private files, complete logs, or conversation transcript are attached.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the reported Cloud Browser navigation to https://www.amazon.co.jp/ and the subsequent browser URL-policy rejection, comparing the requested destination with the internal Chrome error-page URL. Determine which policy layer rejected the action and whether the Always allow setting can trigger a supported re-evaluation. Done means the behavior is classified as intentional or defective and users receive an actionable recovery or diagnostic-report path.
Written by the indexing model from the issue text.
Assessment
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100