JVN#9ADCBB12
Website connection problem when a mobile phone terminal uses specific QR code
Overview
Mobile phone terminals supporting the two-dimensional code (QR code) read function are reported to have a website connection problem. When specific QR code is read, even if a user tries to connect to the URL string in the first line of the two URL lines displayed, the connection is established with the second URL.
This problem has been reported for KDDI mobile phones. The developer provides countermeasure information although they judged this problem not a vulnerability. JVN has publicized this issue in coordination with the developer to make it known to users.
Products Affected
Description
Impact
When specific QR code is read, connection could be established with an unintended site (the site displayed in the second line).
Solution
References
JPCERT/CC Addendum
Credit
Hiromitsu Takagi reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory | |
CPNI Advisory | |
TRnotes | |
CVE | |
JVN iPedia |
JVNDB-2005-000764 |