CVE-2026-108721
Description
Open Computer Use through 1.0.0 on macOS contains an improper case sensitivity handling vulnerability that allows local MCP callers to bypass the password-manager denylist using case-variant bundle identifiers. Attackers, including prompt-injected model turns, can pass identifiers like com.1Password.1Password to get_app_state and action tools to read accessibility trees, capture screenshots, and drive unlocked password manager interfaces.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/iFurySt/open-codex-computer-use
- https://github.com/iFurySt/open-codex-computer-use/blob/8a3a7dec06402db2d760368cb24676ad3ba42c49/packages/OpenComputerUseKit/Sources/OpenComputerUseKit/AppDiscovery.swift#L144-L198
- https://github.com/iFurySt/open-codex-computer-use/blob/8a3a7dec06402db2d760368cb24676ad3ba42c49/packages/OpenComputerUseKit/Sources/OpenComputerUseKit/AppDiscovery.swift#L554-L572
- https://hackmd.io/@haind/rJHI_S6IiMl
- https://www.vulncheck.com/advisories/open-computer-use-through-1.0.0-denylist-bypass-via-case-variant-bundle-id
CWEs
CWE-178
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.