Can a QR code install malware on my phone?
A QR code itself cannot run code, but it can direct your phone to a malicious website that tries to download malware or phish your credentials.
Last reviewed: 1 August 2026
Explanation
QR codes are simply machine-readable links. When you scan one, your phone opens the encoded URL. If that URL leads to a site that exploits a browser vulnerability, mimics a login page to steal credentials, or prompts you to download a malicious app outside your official app store, your device or accounts can be compromised. Scammers place fake QR codes over legitimate ones in public places such as parking meters, restaurant tables, posters, and delivery notices. The risk is especially high if your phone OS or browser is not updated. Always preview the URL before opening it, and be cautious about scanning codes in unexpected places.
Context is the most useful filter. A QR code on a restaurant menu you asked for carries a different risk profile from one on an unsolicited letter, a windscreen flyer, or a sticker at a payment machine — the latter are exactly where 'quishing' thrives, because the situation pressures you to act (pay for parking, release a parcel) before inspecting anything. Codes in printed emails deserve particular suspicion: they exist mainly to route you around link-scanning security filters.
After scanning, the same rules apply as for any link. Check the full domain before interacting, never enter credentials or card details on a page you reached via a code in a public place, and prefer typing the organisation's address yourself when money or logins are involved. The code is only a shortcut; you always have the option of taking the long way, and with payments you usually should.
Common red flags
- QR code on a sticker placed over an existing code in a public place
- URL shown after scanning looks unfamiliar or misspelled
- Code arrives unsolicited by text, email, or post
- Page asks you to log in to an account after scanning
- Page prompts you to download an app from an unofficial source
What to do now
- Preview the URL before opening — most phone cameras show a preview
- Keep your phone OS and browser updated to patch vulnerabilities
- If you visited a suspicious site, change relevant passwords and run a security check
- Report fake QR codes to the venue or local authority responsible for that location
Frequently asked questions
Is it safer to scan QR codes with a dedicated app rather than my camera?
Using a reputable QR scanner that shows a URL preview before loading it adds a layer of protection. However, the risk lies in the destination website, not the scanning method itself.
I scanned a suspicious QR code but didn't enter anything. Am I at risk?
For an up-to-date phone, simply loading a page is rarely enough to cause harm — the danger lies in what you do next: logging in, paying, or installing an app. Close the page, don't revisit it, and make sure your OS and browser are current.