Improper Case Sensitivity Handling Vulnerability in Open Computer Use on macOS
CVE-2026-108721
5.8MEDIUM
What is CVE-2026-108721?
The Open Computer Use application for macOS, up to version 1.0.0, is susceptible to an improper case sensitivity handling flaw. This weakness permits local MCP callers to circumvent the password-manager denylist by utilizing case-variant bundle identifiers. Consequently, attackers can exploit this vulnerability to gain unauthorized access to application features, enabling them to read accessibility trees, capture screenshots, and control open password manager interfaces. The issue highlights significant security implications for user data protection.
Affected Version(s)
open-computer-use 0 <= 1.0.0
References
CVSS V4
Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
