Open URL Navigation Vulnerability in Quasar Framework Affecting iOS Environments
CVE-2026-106101

3.1LOW

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106101?

The Quasar Framework, a popular tool for building Vue.js user interfaces, contains a vulnerability in its openURL() utility that is triggered in iOS environments. Prior to version 2.32.2, the utility incorrectly trusted the window.SafariViewController global, allowing an attacker to manipulate browser behavior. By rendering user-controlled HTML through components like QEditor, malicious actors can create a named SafariViewController element. This results in named-property resolution altering the expected native bridge object, leading to a TypeError during subsequent openURL() calls. This disruption affects critical workflows, such as external navigation, login redirects, and payment processes. The vulnerability is addressed in version 2.32.2, emphasizing the necessity of keeping systems updated.

Affected Version(s)

quasar < 2.32.2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.