How a QR code can fool iOS 11's Camera app into opening evil.com rather than nice.co.uk
A security researcher based in Germany has identified a flaw in the way Apple's iOS 11 handles QR codes in its Camera app.
Last year, with the launch of iOS 11, Apple gave its Camera app the ability to automatically recognize QR codes.
Over the weekend, Roman Mueller found that this feature has a bug that can be used to direct people to unexpected websites.
The first step involves creating a QR code from a URL, such as this one:
https://xxx\@facebook.com:443@infosec.rm-it.de/