Farzan Karimi, who previously led red teams at Google and Electronic Arts, published research showing that QR-code platforms' custom-domain feature can be used to seize companies' branded QR addresses. Demonstrated against QR Tiger's "Own Short Domain" feature, the weakness is that the platform verified only that a CNAME record existed, never who was claiming it — so any account holder could claim a subdomain still pointing at the platform after a business stopped using the service without removing its DNS record, and take it over in under a minute. Because the codes are printed, the effect reaches existing campaigns: Karimi confirmed to iTnews that a QR code generated for a campaign remains at risk for as long as the stale record stands, and printed codes cannot be revoked with a software update. He says he found hundreds of vulnerable companies across manufacturing, healthcare, financial services and technology, published no count and named none, and reported that QR Tiger had not fixed the flaw five months after he reported it. His proposed control — an ownership token published in a TXT record — is standard practice on other SaaS platforms.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-26 |
| Source | iTnews |
| Reliability | Tier 3 |