macOS Computer Use stops native Yandex session with URL-not-allowed error after successful use
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
What version of the Codex App are you using?
26.911.61220, build 9647 (installed desktop app bundle metadata).
What subscription do you have?
ChatGPT subscription; exact tier not confirmed for this report.
What platform is your computer?
macOS 26.2, arm64. Native Yandex browser, bundle ID ru.yandex.desktop.yandex-browser.
What issue are you seeing?
After more than an hour of successful, user-authorized browser work, Computer Use stopped a native Yandex session while reading an Avito account page. The blocked action only inspected the interface; it did not submit a payment, publish an item, or change account settings.
At 2026-09-17 20:31:58.305 UTC (23:31:58.305 Moscow time), mcp__cua_repl.js returned this error on yandex.getAXState({emit:false}):
This session has been stopped because Computer Use is not allowed on the current browser URL. Stop your work and send a final message noting why the session has been ended. Note that Computer Use is not allowed on this URL even if the user navigates to it themselves.
The intended page was https://www.avito.ru/tariff/cpa/profile. We cannot determine whether this is an intended restriction or a regression. The denial came from Computer Use; this report does not assert that Avito blocked the account.
What steps can reproduce the bug?
Observed sequence (not retried after the denial):
- Use the native Yandex browser through Computer Use in a local desktop task, with the user signed into their own Avito account.
- Perform authorized account administration successfully in the same session.
- Navigate to
https://www.avito.ru/tariff/cpa/profile. - Read the accessibility state to inspect the displayed account budget.
- Receive the URL-not-allowed error and a mandatory session stop.
Reproducibility is unknown because we respected the stop and did not attempt another browser or tool to bypass it.
What is the expected behavior?
If this page is allowed, read-only inspection should continue. If the URL is intentionally restricted, please clarify the applicable restriction and supported recovery path. Please investigate which URL and rule caused the denial and whether the transition from successful work to a stopped session was expected.
Additional information
In-app feedback submitted by the user: no-active-thread-01a0b13f-a295-7d43-8eb1-3a1a3fdc4b56.
During navigation, an earlier accessibility snapshot showed the Avito title and requested address while the window URL still read file:///. This is only an observation during page loading, not an established cause of the denial.
No raw session logs, account identifiers, email address, customer conversations, credentials, tokens, or cookies are included in this public report.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the mcp__cua_repl.js entry point and the yandex.getAXState({emit:false}) call. Determine which URL and rule produced the denial, then verify whether the session stop is expected for the Avito page; done means documenting the applicable restriction or reproducing a supported read-only path if the page should be allowed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- macos
- Domain
- desktop, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100