

I keep hearing about malicious QR codes, but how does it actually work? Unless there’s a serious vulnerability, how is it different from clicking on any link?
It has been a few years since I worked as a junior in offensive security, but that has been something I could never figure out when I looked into it.
Hmm, I guess you could use it for a pretty good phishing attempt. Just show a fake google login page and you’re set, or maybe a fake .apk download “to confirm the captcha”, but other than that, I don’t really see a vector of attack.


I’m out of the loop, what did you find?
EDIT: I guess you’re talking about this? From a first reddit page about why is it down I could find.