Luuk @luuk.dev · May 28

I hate this. One could totally recreate this with a malicious link hidden behind the QR code.

4 likes 2 replies

?

Replies

Luuk · May 28

Besides the classic QR-switcharoo, it 'leaks' the captcha-protected link to Google Play Services on your phone. Brilliant.

Abel · May 28

yeah the workaround is to now build some chrome extension to read the QR code and verify its hash against valid apps and only then proceed with scanning or smth. dumb nightmarefuel