Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Integration Causes Client-Side Denial of Service
🔗 CVE IDs covered (1)
📋 Description
Summary
A DOM Clobbering vulnerability exists in Quasar's openURL() utility when handling the iOS SafariViewController bridge.
The vulnerable implementation only checks whether window.SafariViewController exists before invoking it as a native bridge object. An attacker who can inject HTML content containing a named element such as <a id="SafariViewController"> can cause the browser to expose that element as window.SafariViewController.
When openURL() is later called in an iOS environment, Quasar incorrectly treats the DOM element as the native bridge object and attempts to invoke bridge methods that do not exist, resulting in:
TypeError: window.SafariViewController.isAvailable is not a function
This can cause client-side denial of service and break navigation-related workflows in Quasar applications.
Details
Quasar provides the openURL() utility to open external URLs. On iOS platforms, this utility supports integration with the native SafariViewController bridge.
The vulnerable code is located in:
ui/src/utils/open-url/open-url.js
The affected logic is:
if (Platform.is.ios && window.SafariViewController !== void 0) {
window.SafariViewController.isAvailable(available => {
if (available) {
window.SafariViewController.show({ url }, noop, reject)
}
})
}
The issue is that Quasar only verifies that window.SafariViewController is not undefined. It does not verify whether the value is the expected native bridge object or whether required methods such as isAvailable() and show() are valid functions.
Modern browsers expose elements with specific id or name attributes as properties of the global window object. Therefore, attacker-controlled HTML such as:
<a id="SafariViewController"></a>
can cause:
window.SafariViewController
to resolve to an HTMLAnchorElement instead of the expected native bridge object.
When Quasar later executes:
window.SafariViewController.isAvailable(...)
the DOM element is incorrectly treated as the bridge object, causing:
TypeError: window.SafariViewController.isAvailable is not a function
The root cause is insufficient validation of browser-controlled global properties before using them as trusted native bridge objects.
The vulnerability was verified through the Quasar QEditor rendering path. When attacker-controlled HTML content is rendered into the DOM and creates the SafariViewController named element, subsequent calls to openURL() fail.
Additional component-level affected paths were identified in QSelect and QChatMessage when applications enable HTML rendering features and provide attacker-controlled content. These paths require specific application configurations and were not used as the primary end-to-end reproduction.
PoC
Steps to reproduce
- Render attacker-controlled HTML content through a Quasar HTML rendering component such as
QEditor. - Insert the following payload:
<a id="SafariViewController" href="#bridge">
SafariViewController
</a>
- Verify that the browser exposes the element as a global property:
window.SafariViewController
The value resolves to the injected DOM element instead of the expected native bridge object.
- Trigger a normal workflow that invokes:
openURL('https://example.com')
- Observe the browser console output:
TypeError: window.SafariViewController.isAvailable is not a function
The URL opening workflow fails because Quasar attempts to invoke native bridge methods on the DOM element.
The same underlying issue can also affect other HTML rendering paths such as QSelect and QChatMessage when attacker-controlled HTML is rendered and the application later calls openURL().
Impact
This vulnerability is a client-side DOM Clobbering and type confusion issue affecting Quasar applications that use the iOS SafariViewController integration. An attacker who can control HTML content rendered into the application DOM may cause Quasar's openURL() functionality to fail by replacing the expected native bridge object with a DOM element through browser named property resolution.
Potentially affected workflows include external URL navigation, OAuth/login redirects, help or documentation links, payment flows, third-party service redirects, and other application actions that rely on URL opening functionality.
The confirmed impact is client-side denial of service and navigation or workflow disruption. When the vulnerable condition is triggered, Quasar throws an exception while attempting to invoke methods on the clobbered SafariViewController object, preventing the expected URL opening behavior.
🎯 Affected products1
- npm/quasar:<= 2.32.1
🔗 References (5)
- https://github.com/quasarframework/quasar/security/advisories/GHSA-89vp-x45c-52cq
- https://nvd.nist.gov/vuln/detail/CVE-2026-106101
- https://github.com/quasarframework/quasar/commit/52d874bf55309dd3656fb02aed033ab025d477ec
- https://github.com/quasarframework/quasar/releases/tag/quasar-v2.32.2
- https://github.com/advisories/GHSA-89vp-x45c-52cq