Improper Case Sensitivity Handling Vulnerability in Open Computer Use on macOS
CVE-2026-108721

5.8MEDIUM

Key Information:

Vendor

Ifuryst

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108721?

The Open Computer Use application for macOS, up to version 1.0.0, is susceptible to an improper case sensitivity handling flaw. This weakness permits local MCP callers to circumvent the password-manager denylist by utilizing case-variant bundle identifiers. Consequently, attackers can exploit this vulnerability to gain unauthorized access to application features, enabling them to read accessibility trees, capture screenshots, and control open password manager interfaces. The issue highlights significant security implications for user data protection.

Affected Version(s)

open-computer-use 0 <= 1.0.0

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.