Open URL Navigation Vulnerability in Quasar Framework Affecting iOS Environments
CVE-2026-106101
What is CVE-2026-106101?
The Quasar Framework, a popular tool for building Vue.js user interfaces, contains a vulnerability in its openURL() utility that is triggered in iOS environments. Prior to version 2.32.2, the utility incorrectly trusted the window.SafariViewController global, allowing an attacker to manipulate browser behavior. By rendering user-controlled HTML through components like QEditor, malicious actors can create a named SafariViewController element. This results in named-property resolution altering the expected native bridge object, leading to a TypeError during subsequent openURL() calls. This disruption affects critical workflows, such as external navigation, login redirects, and payment processes. The vulnerability is addressed in version 2.32.2, emphasizing the necessity of keeping systems updated.
Affected Version(s)
quasar < 2.32.2
