So: Oddly enough, if you make a QR code that tells you to go somewhere, the camera will take you to where the QR code tells you to go, even if you tell someone that the QR code goes someplace else. This trend of ‘reporting’ security problems that are not security problems at all is getting stupid now.
A security researcher based in Germany has identified a flaw in the way Apple’s iOS 11 handles QR codes in its Camera app.
Last year, with the launch of iOS 11, Apple gave its Camera app the ability to automatically recognize QR codes.
Over the weekend, Roman Mueller found that this feature has a bug that can be used to direct people to unexpected websites.
The first step involves creating a QR code from a URL, such as this one:
https://xxx\@facebook.com:443@infosec.rm-it.de/
If you then open the Camera app under iOS 11.2.6 (the most recent release) and point the device’s camera at the QR code made from that URL, it will immediately recognize the presence of a QR code, parse the embedded URL, and ask whether you want to open “facebook.com” in Safari.
The problem is that the the app will open a different website – “infosec.rm-it.de”
Robin Edgar
Organisational Structures | Technology and Science | Military, IT and Lifestyle consultancy | Social, Broadcast & Cross Media | Flying aircraft