Researcher Identified QR Tiger Hijacking Flaw

A security researcher revealed a vulnerability that allows attackers to seize control of branded QR code subdomains.

Updated on Sept. 25, 2026 in Cybersecurity

Researcher Identified QR Tiger Hijacking Flaw

Live Poll

Do you trust that companies effectively manage your digital security and personal data?

Security researcher Farzan Karimi published findings on a subdomain hijacking vulnerability affecting QR Tiger. The flaw allows unauthorized users to take over web addresses pointed at the platform in under one minute.

Why it matters

The vulnerability persists because companies often fail to remove stale CNAME DNS records after discontinuing their use of specific QR code services. This oversight leaves branded subdomains open to hijacking by malicious actors.

The hijacking process relies on stale CNAME records, allowing attackers to claim subdomains that no longer point to an active registration. Exploitation of this flaw takes under one minute to complete.

The players

Farzan Karimi

He is the security researcher who identified the subdomain hijacking vulnerability in the QR Tiger platform.

QR Tiger

It is a QR code generation provider that contains a custom domain feature currently affected by a subdomain hijacking vulnerability.

Mohamed Abdelbasset Elnouby

He is the security researcher who originally published the QRLJacking attack methodology in 2016.

The details

Attackers exploit the custom domain feature by identifying subdomains that remain pointed at QR Tiger servers despite being abandoned by the original owner. Karimi identified hundreds of vulnerable companies across multiple sectors and plans to release a scanning tool called QR Tiger King on GitHub.

Timeline

  1. 2016: QRLJacking attack published by Mohamed Abdelbasset Elnouby.

  2. April 2026: Karimi reported the flaw to QR Tiger.

  3. September 2026: Karimi published the QR Jacking research.

The Tech Race

This research follows a pattern established by the 2016 QRLJacking research regarding the inherent risks in QR code infrastructure. The ongoing issue highlights the persistent challenge of securing legacy DNS configurations against modern hijacking techniques.

Companies using custom branded subdomains for QR codes should immediately audit their DNS settings for stale CNAME records to prevent hijacking. Users scanning QR codes should remain cautious, as attackers can redirect these addresses to malicious web content.

The takeaway

Organizations must prioritize the cleanup of DNS records to close security gaps that remain after abandoning third-party services. This incident serves as a reminder that proper decommission of digital infrastructure is essential for maintaining brand integrity and user safety.

Further reading

Learn more about evolving digital threats in our Cybersecurity section.

Source note: This article includes information reported by ITnews.

Live Poll

Do you trust that companies effectively manage your digital security and personal data?