Summary
On macOS, Codex's built-in Browser refuses to inspect an open, authenticated https://propfinder.app/nfl tab even though Settings → Browser → Agent permissions shows Browsing: Always allow for https://propfinder.app (and for Default). The user can open the site manually. This blocks a read-only, scheduled research workflow.
Steps and observed behavior
- Open the site in the built-in browser and sign in.
- Set
https://propfinder.app → Browsing to Always allow in Agent permissions. The visible default is also Always allow.
- Ask Codex to inspect the open tab, including with an explicit tab mention.
- Browser Use rejects the action before page inspection:
Browser Use rejected this action due to browser security policy. Reason: A saved user permission setting blocks this action. Browser use cannot access https://propfinder.app because the user has a saved preference that blocks it.
The permission mismatch persisted across retries after the user confirmed the setting. A read-only check of local Codex configuration also showed [browser_use.origins."https://propfinder.app"] access = "allow"; it did not establish why Browser Use applies a denial. The same site was accessible to Codex in a different task on September 19, 2026. During a scheduled task on September 20, the first opening attempt was declined; subsequent attempts in this task report a saved block. This chronology does not prove a cause.
Expected
The explicit origin-level allowance permits the authorized read-only browser operation, or the UI identifies an overriding policy and provides a supported way to recover. It should not attribute the rejection to a saved user block that contradicts the visible setting.
Impact and privacy
The scheduled task cannot produce its requested output from the authenticated site. No account details, credentials, session identifiers, screenshots, site data, or full logs are included here. No alternate browser surface or policy workaround was used.
Potentially related symptom: #43754 and #44895.
Summary
On macOS, Codex's built-in Browser refuses to inspect an open, authenticated
https://propfinder.app/nfltab even though Settings → Browser → Agent permissions shows Browsing: Always allow forhttps://propfinder.app(and for Default). The user can open the site manually. This blocks a read-only, scheduled research workflow.Steps and observed behavior
https://propfinder.app→ Browsing to Always allow in Agent permissions. The visible default is also Always allow.The permission mismatch persisted across retries after the user confirmed the setting. A read-only check of local Codex configuration also showed
[browser_use.origins."https://propfinder.app"] access = "allow"; it did not establish why Browser Use applies a denial. The same site was accessible to Codex in a different task on September 19, 2026. During a scheduled task on September 20, the first opening attempt was declined; subsequent attempts in this task report a saved block. This chronology does not prove a cause.Expected
The explicit origin-level allowance permits the authorized read-only browser operation, or the UI identifies an overriding policy and provides a supported way to recover. It should not attribute the rejection to a saved user block that contradicts the visible setting.
Impact and privacy
The scheduled task cannot produce its requested output from the authenticated site. No account details, credentials, session identifiers, screenshots, site data, or full logs are included here. No alternate browser surface or policy workaround was used.
Potentially related symptom: #43754 and #44895.