What happened
VulnCheck published CVE-2026-108721 (published 2026-10-11, CVSS 5.3 v3.1, CWE-178) for Open Computer Use ≤ 1.0.0: the macOS password-manager denylist is bypassable via case-variant bundle IDs, so prompt-injected model turns can reach and drive unlocked password-manager interfaces through computer-use tooling. Verified against NVD REST API.
Why it matters
Computer-use agents hold powerful UI-driving and screenshot capabilities; a denylist bypass converts that into credential theft from unlocked password managers on developer/officer laptops. The specific prompt-injection path makes this a real agent-execution attack class for MCP computer-use deployments.
Attack vector
Local MCP callers (including prompt-injected agent turns) pass a case-variant bundle identifier (CWE-178, e.g. com.1Password.1Password) to get_app_state/action tools; the case-sensitive denylist comparison lets them read accessibility trees, capture screenshots and drive an unlocked password manager UI.
Affected systems
iFurySt Open Computer Use (open-computer-use / OpenComputerUseKit) through 1.0.0 on macOS
Mitigation
Upgrade past 1.0.0 and/or harden the denylist to a case-insensitive canonical comparison; restrict computer-use tool access and monitor for get_app_state/action calls touching password-manager apps. Advisory: https://www.vulncheck.com/advisories/open-computer-use-through-1.0.0-denylist-bypass-via-case-variant-bundle-id