Description
Open Computer Use through 1.0.0 on macOS contains an improper case sensitivity handling vulnerability that allows local MCP callers to bypass the password-manager denylist using case-variant bundle identifiers. Attackers, including prompt-injected model turns, can pass identifiers like com.1Password.1Password to get_app_state and action tools to read accessibility trees, capture screenshots, and drive unlocked password manager interfaces.
Published: 2026-10-11
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: Potential Data Breach
Action: Assess Impact
AI Analysis

Impact

Open Computer Use 1.0.0 for macOS contains an improper case‑sensitivity handling flaw that lets local MCP callers bypass the password‑manager denylist by using case‑variant bundle identifiers such as com.1Password.1Password. This allows attackers, including those injecting prompts into models, to call get_app_state and action services and then read accessibility trees, capture screenshots, and drive unlocked password manager interfaces, exposing sensitive credential data and other user information.

Affected Systems

The vulnerability affects the macOS application Open Computer Use version 1.0.0, released by iFurySt. No other versions or vendor products are listed as impacted.

Risk and Exploitability

With a CVSS score of 5.8 the vulnerability has moderate severity. The EPSS score is not available and the issue is not listed in CISA KEV, indicating that there is no large‑scale exploit activity recorded yet. Exploitation requires local access to the MCP system and the ability to invoke get_app_state and action services. Once invoked, the attacker can read accessibility trees and capture screenshots, providing access to ordinary or password manager user data. The denial‑list bypass and case‑variant bundle identifier trick are explicit in the description, confirming the attack path as a local privilege escalation via denial‑list manipulation.

Generated by OpenCVE AI on October 11, 2026 at 13:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify whether a newer release of Open Computer Use addresses this case‑variant bundle identifier bypass and install it if available.
  • Restrict local MCP caller privileges by limiting which applications can invoke get_app_state and action services, for example using macOS access controls or sandboxing.
  • Revoke or disable accessibility permissions for applications not listed on the official denylist to prevent unauthorized access to password manager interfaces.

Generated by OpenCVE AI on October 11, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Open Computer Use through 1.0.0 on macOS contains an improper case sensitivity handling vulnerability that allows local MCP callers to bypass the password-manager denylist using case-variant bundle identifiers. Attackers, including prompt-injected model turns, can pass identifiers like com.1Password.1Password to get_app_state and action tools to read accessibility trees, capture screenshots, and drive unlocked password manager interfaces.
Title Open Computer Use through 1.0.0 Denylist Bypass via Case-Variant Bundle ID
Weaknesses CWE-178
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:31.981Z

Reserved: 2026-10-11T01:52:29.003Z

Link: CVE-2026-108721

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:15.470

Modified: 2026-10-11T13:17:15.470

Link: CVE-2026-108721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:00:18Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity