Impact
Open Computer Use 1.0.0 for macOS contains an improper case‑sensitivity handling flaw that lets local MCP callers bypass the password‑manager denylist by using case‑variant bundle identifiers such as com.1Password.1Password. This allows attackers, including those injecting prompts into models, to call get_app_state and action services and then read accessibility trees, capture screenshots, and drive unlocked password manager interfaces, exposing sensitive credential data and other user information.
Affected Systems
The vulnerability affects the macOS application Open Computer Use version 1.0.0, released by iFurySt. No other versions or vendor products are listed as impacted.
Risk and Exploitability
With a CVSS score of 5.8 the vulnerability has moderate severity. The EPSS score is not available and the issue is not listed in CISA KEV, indicating that there is no large‑scale exploit activity recorded yet. Exploitation requires local access to the MCP system and the ability to invoke get_app_state and action services. Once invoked, the attacker can read accessibility trees and capture screenshots, providing access to ordinary or password manager user data. The denial‑list bypass and case‑variant bundle identifier trick are explicit in the description, confirming the attack path as a local privilege escalation via denial‑list manipulation.
OpenCVE Enrichment