Sceawere

Vulnerability Detail

CVE-2026-108721UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Open Computer Use Case-Sensitivity Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
iFurySt
Product
open-computer-use
Attack Type
Improper Handling of Case Sensitivity
Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Open Computer Use through 1.0.0 on macOS contains an improper case sensitivity handling vulnerability that allows local MCP callers to bypass the password-manager denylist using case-variant bundle identifiers. Attackers, including prompt-injected model turns, can pass identifiers like com.1Password.1Password to get_app_state and action tools to read accessibility trees, capture screenshots, and drive unlocked password manager interfaces.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-11T13:17:15.470Z",
  "pubdate": "2026-10-11T13:17:15.470Z",
  "executiveSummary": "Open Computer Use versions up to 1.0.0 on macOS are susceptible to an improper case-sensitivity handling vulnerability within its security enforcement mechanisms. This flaw allows local Model Context Protocol (MCP) callers to circumvent the password-manager denylist by providing case-variant bundle identifiers. By exploiting this discrepancy, an attacker can bypass restrictions intended to prevent unauthorized interaction with sensitive applications. The vulnerability enables attackers—including those leveraging prompt-injected model turns—to execute arbitrary commands against protected software. Successful exploitation grants the ability to read accessibility trees, capture screen content, and programmatically drive unlocked password manager interfaces. This bypass poses a significant risk to the confidentiality and integrity of credentials managed by applications like 1Password, as it effectively renders existing denylist-based security controls ineffective against variant-based identifier spoofing.",
  "technicalDetails": "The vulnerability resides in the input validation logic used by Open Computer Use to enforce a denylist of sensitive applications. The system employs a case-sensitive string comparison or indexing method to evaluate bundle identifiers provided to the 'get_app_state' and 'action' tools. Because macOS bundle identifiers are typically treated as case-insensitive at the system file level, but evaluated inconsistently by the Open Computer Use security filter, an attacker can bypass the check by providing a non-canonical casing of a restricted bundle ID (e.g., 'com.1Password.1Password' instead of a registered canonical form).\nThe attack flow begins when an MCP caller initiates a request to the affected Open Computer Use toolset. When the tool receives the target application identifier, the internal security mechanism performs a validation check against its denylist. Due to the failure to normalize the input identifier to a canonical case before comparison, the filter fails to identify the target as a restricted password manager. Consequently, the request is permitted to proceed to the underlying macOS accessibility APIs.\nOnce the filter is bypassed, the attacker achieves interaction with the target application’s UI hierarchy. By invoking 'get_app_state', the attacker can extract the accessibility tree of the password manager, potentially exposing the structure of protected input fields or credential views. By invoking 'action' tools, the attacker can simulate keyboard and mouse events to drive the interface. If the password manager is currently unlocked, the attacker can perform operations as the authenticated user, such as copying secrets to the clipboard or modifying existing entries. This vulnerability requires local access or a compromised MCP flow capable of executing arbitrary tools, effectively elevating the privileges of a standard model interaction to those of a GUI-automation agent capable of bypassing application-level security policies."
}
CVE-2026-108721: Open Computer Use Case-Sensitivity Bypass (MEDIUM Severity, CVSS: 5.3) | Sceawere