←back to thread

527 points lxm | 1 comments | | HN request time: 0.208s | source
Show context
chpmrc ◴[] No.27674446[source]
How long before someone exploits this?

- Build an app that injects malware but also shows the restaurant's menu. Give it the same name as the restaurant.

- Go to the restaurant, overlay your QR code sticker on top of the restaurant's.

- When someone scans the code they are asked to install "[Restaurant's name] menu", obviously they are going to do it.

- They open the app -> malware is activated, menu is shown. Profit.

replies(2): >>27674568 #>>27675363 #
1. dna_polymerase ◴[] No.27675363[source]
I'm totally going to use my 0day iOS sandbox escape to steal the $50 order from the restaurant down the street.