CVE-2026-106101Low· 3.1▾ TwilightPoC availableQuasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 17.1 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.32.2, the openURL() utility in ui/src/utils/open-url/open-url.js trusted window.SafariViewController whenever that global existed in an iOS environment. Attacker-controlled HTML rendered by components such as QEditor can create a named SafariViewController element, causing browser named-property resolution to replace the expected native bridge object. A later openURL() call then invokes isAvailable() on the element, throws a TypeError, and disrupts external navigation, login redirects, payment redirects, and other URL-opening workflows. QSelect and QChatMessage HTML-rendering configurations can expose the same trigger when they render attacker-controlled HTML. This issue is fixed in version 2.32.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106106High· 7.1Quasar Framework is a framework for building high-performance Vue.js user interfaces
CVE-2026-106104High· 8.7Quasar Framework is a framework for building high-performance Vue.js user interfaces
CVE-2026-106103High· 7.1Quasar Framework is a framework for building high-performance Vue.js user interfaces
CVE-2026-106107High· 8.3Quasar Framework is a framework for building high-performance Vue.js user interfaces
CVE-2026-106109Medium· 4.1Quasar Framework is a framework for building high-performance Vue.js user interfaces
CVE-2026-106105High· 8.4Quasar Framework is a framework for building high-performance Vue.js user interfaces