Computer-Use and TOCTOU: What You Click Is Not What You Get! (opens in new tab)
Last year, Jun Kokatsu disclosed an with ChatGPT Operator by exploiting a race condition. I was wondering if I could reproduce this attack chain, and this post describes the results of that research. I had this post drafted for months, and yesterday at the I included a video demo of this attack in my talk and that reminded me that I should finally publish this.
Read the original article