Hit Subscribe!

Don’t Be a Noob, Subscribe Already!

iPhone

How To: 13 QR Code Scanners That Won’t Send You to Malicious Webpages on Your iPhone

The default Camera app got a few more tricks up its sleeves when iOS 11 was released, and the best addition by far was the inclusion of a built-in QR code reader since that meant no more third-party apps just for QR code scanning. However, Apple’s built-in QR code scanner did have a vulnerability at one point that would let hackers direct you to a compromised website without you even noticing it.

While old by now, the vulnerability in question, discovered by security consultant Roman Mueller, happened when the Camera app scanned a QR code with a website link. After scanning, it did not correctly parse the URL within, which could result in the notification that popped up showing one domain name, while tapping through would take you to a completely different one.

  • Don’t Miss: Everything You Need to Disable on Your iPhone

Using Roman’s example, the URL in the QR code would be embedded as such:

https://xxx@facebook.com:443@infosec.rm-it.de/

And after scanning the QR code, the pop-up in your Camera app would have said “Open ‘facebook’ in Safari” but would actually take you to infosec.rm-it.de instead.

All a hacker needed to do to trick you into giving up your credentials was create a convincing clone of the website you thought you were going to, complete with a URL that looked almost the same as the one it’s masquerading as, then put it out there on the web and phish until they had enough of what they wanted.

While Roman discovered this in iOS 11.2.1, we had tested it in iOS 11.2.6, the iOS 11.3 beta, and iOS 11.3, and it persisted in all of those versions. The glitch was reported to Apple on Dec. 23, 2017, but was not officially addressed until April 24, 2018, when iOS 11.3.1 was released to the public.

So if you’re running anything from iOS 11.3.1 or later, such as iOS 12 or iOS 13, you don’t need to worry about the vulnerability. Still, you may be interested in third-party QR code readers if you don’t like or trust Apple’s.

Update to iOS 11.3.1 or Later to Fix This Issue

Apple finally fixed the issue, labeled by Apple as CVE-2018-4187, in the iOS 11.3.1 update on April 24, 2018. So, if you like the idea of using your Camera app to scan QR codes, simply update to iOS 11.3.1 or later, such as iOS 12 or iOS 13, on your iPhone.

  • More Info: iOS 11.3.1 Finally Fixed the QR Code-Scanning Vulnerability

Disable the Camera’s Built-in QR Code Scanner

Whether or not you only scan QR codes daily or almost never, you’ll want to disable the QR code scanner in the Camera app if you’re worried about it from a security perspective. Even though Apple fixed the issue, it just goes to show how easy it is for hackers to take advantage of you using stock Apple apps.

While the chances of you scanning a malicious QR code are relatively low, you can never be too safe. Either update to iOS 11.3.1 or later or open up your Settings app, tap on “Camera,” then toggle off “Scan QR Codes.”

Use a Third-Party QR Code Scanner Instead

If you find yourself scanning a lot of QR codes and don’t want to update to iOS 11.3.1 or later just yet, you might want to go back to one of your third-party QR code scanners until you’re ready to trust Apple again.

We personally tested all of the free QR code readers below using the same vulnerability, and they all failed to load the malicious webpage properly. Some did a web search for the string while others just failed to read the URL at all, treated it as an email link, or just crashed the app. Either way, it was obvious and did not go directly to the malicious website.

  • QR Reader for iPhone
  • QR Scanner and Barcode Reader (no longer available)
  • QR Code Reader & QR Scanner!
  • QR Code Reader ·
  • QR Code Reader – QR Scanner & QR Code Generator (no longer available)
  • QR Code Scanner – QrScan
  • QR Code Reader & QR Scanner
  • QR Code Reader & Code Scanner
  • QR_Scanner
  • Barcode Scanner – QR Scanner
  • Bakodo – Barcode Scanner and QR Bar Code Reader
  • QR Code Scanner – QR Reader & Barcode Scanner
  • FreeScanner
Three different scanners reading the same QR code.

Like previously mentioned, the chances that you take a snapshot of a malicious QR code are low, but it’s definitely possible, so a third-party app might be good if you’re running iOS 11.3 or lower. Otherwise, make sure to install iOS 11.3.1 or later to be protected.

Editor’s note: Article updated on April 24, 2018, when Apple released iOS 11.3.1.

  • Follow Gadget Hacks on Facebook, Twitter, YouTube, and Flipboard
  • Follow WonderHowTo on Facebook, Twitter, Pinterest, and Flipboard

Just updated your iPhone? You’ll find new features for Podcasts, News, Books, and TV, as well as important security improvements and fresh wallpapers. Find out what’s new and changed on your iPhone with the iOS 17.5 update.

Cover photo and screenshots by Justin Meyers/Gadget Hacks

Source

 

Hey there, just a heads-up: We’re part of the Amazon affiliate program, so when you buy through links on our site, we may earn a small commission. But don’t worry, it doesn’t cost you anything extra and helps us keep the lights on. Thanks for your support!”

Avatar

Geeks Gadgets

About Author

Leave a comment

Your email address will not be published. Required fields are marked *

Productivity & Shortcuts

iPhone

“iPhone Home Screen: Hide & Show Pages like a Boss!”

Learn how to effectively hide and show pages on your iPhone home screen like a pro with our expert tips

Add A Knowledge Base Question !

You will receive an email when your question will be answered.

+ = Verify Human or Spambot ?