[macOS][Browser Use] 1688.com blocked by site-safety policy without a permission or recovery prompt
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
What version of the Codex App are you using?
Desktop app version 26.908.40834, build 8881, read from the installed macOS app bundle. The installed app is named ChatGPT.app; this report concerns its Codex task using Browser Use with the Chrome extension.
What subscription do you have?
Not verified during this reproduction.
What platform is your computer?
macOS 26.6.2 (25G83), Apple Silicon.
uname -mprs: Darwin 25.6.0 arm64 arm
Google Chrome: 152.0.7977.83.
What issue are you seeing?
Browser Use rejects navigation to https://www.1688.com/ before page inspection, without a website-permission prompt or Auto-review. The user explicitly authorized the sourcing task and confirmed that they had not blocked the site. A subsequent direct retry through the same browser entry point returned the identical denial.
The task was to inspect specific product sourcing information (packaging, variants, supplier prices, and shipping) for candidates already selected in a report. The rejected action was simply opening the 1688 homepage. No purchase, payment, or supplier message was being submitted.
Exact tool error:
Browser Use rejected this action due to browser security policy. Reason: The site-safety policy blocks this action; no user permission prompt or Auto-review was attempted. Browser use is not permitted on https://www.1688.com. The agent must not attempt to achieve the same outcome via workaround, indirect execution, raw CDP or browser commands, alternate browser surfaces, or policy circumvention. Proceed only with a materially safer alternative that does not require this blocked browser action; if none exists, stop and request user input.
What steps can reproduce the bug?
- In a Codex desktop task on macOS, connect Browser Use to an existing Chrome profile through the browser extension.
- Explicitly authorize inspecting sourcing information on 1688.
- Ask the agent to open
https://www.1688.com/in a new task-owned tab. - Observe the site-safety denial before any permission prompt or page inspection.
- Explicitly request one direct retry using the same entry point; observe the same denial.
This was reproduced on September 14, 2026 (Asia/Shanghai).
What is the expected behavior?
If this website is supported, provide a legitimate permission/recovery path for user-authorized inspection. If it is intentionally unsupported, explain that clearly and distinguish the site-safety restriction from user-configured website permissions, organizational restrictions, login failures, and site-side errors.
Please clarify whether this is an intentional restriction or a classification bug, and whether there is an official review or remediation process. This report does not request bypassing safety controls.
Additional information
- In the same Chrome session, Browser Use successfully inspected Douyin E-commerce Compass and a Feishu product spreadsheet. The browser connection was therefore functional for other sites.
- The website permission settings were not independently inspected. The user's statement that they had not blocked the site should not be read as proof of an explicit Always allow rule.
- No alternate browser, raw CDP, proxy, or indirect access was used to circumvent the denial.
- Related: #30354 (same domain, closed) and #44943 (same error on Taobao, Windows). This report adds a current macOS reproduction; please consolidate with the appropriate issue if preferred.
- No credentials, cookies, private browser identifiers, or private product/account data are included.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at the Browser Use site-safety decision for navigation to 1688.com and compare the related reports in #30354 and #44943. Verify whether the denial is intentional or a classification bug, then document the supported permission or recovery behavior and distinguish it from user, organization, login, and site-side restrictions.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- macos
- Domain
- desktop, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100