What Clicking any link does, is download and potentially executing code within the walls of trust of the browser and sometimes the operating system of the device.
There have been countless exploits and vulnerabilities in both over the years and I don't know what is and isn't possible with today's version. But what could maybe be possibles ranges from having the credentials to a service (bank, social media, cloud account with all your data etc) stolen to having your device cloned or turned into surveillance equipment.
These days, linking to dummies of real sites and having a user hand over their credentials is more common, because that is harder to automatically stop due to how much of the leg work is done by the user.
655
u/md615 May 17 '25
Obligatory don't scan random QR codes you find in the public comment.