Can a QR Code Contain a Virus? What It Can Really Do

Can a QR Code Contain a Virus? What It Can Really Do

A QR code can’t contain a virus that infects your phone when you scan it. A QR code only stores a small amount of text, usually a web address, and scanning just reads that text. What a QR code can do is point you to a website that tries to trick you into installing malware or typing in your passwords. So the danger is real, but it happens after the scan, when you open what the code contains.

What a QR code can actually hold #

A QR code is a grid of squares that encodes text. Denso Wave, which invented the format, puts the maximum at about 3 KB for the largest code at the lowest error correction level. Most real codes hold far less: a web address, a Wi-Fi login, a contact card or a sentence of text.

That’s not enough room for most real malware, and more importantly, your phone doesn’t run QR code contents as a program. It reads the text and offers an action: open this link, join this network, save this contact. Nothing happens until you tap.

For more on the limits, see how much data a QR code can hold.

How QR codes are used to spread malware #

The code is the delivery method. The harm comes from where it sends you.

The code opens a page that pushes an app, a file or a configuration profile. The FTC warns that scam QR codes can install malware that steals your personal information without you realizing it. On Android, that usually means an app installed from outside Google Play. On iPhone, it’s more often a request to install a profile or a push to a fake App Store-style page.

The FBI’s 2025 warning about QR codes in unsolicited packages describes the same pattern: the code leads to a site that collects personal and financial details or tries to install malicious software. Its advice includes being careful before granting permissions to websites and apps.

Far more common than malware. The code opens a copy of a bank, parking, delivery or sign-in page, and you type in what the scammer wants. No virus needed. This is called quishing; see what quishing is.

In rare cases, a malicious web page can exploit a bug in an out-of-date browser or phone operating system. That’s why the FTC’s QR code advice includes keeping your phone’s software updated. Updates close exactly these holes.

Codes that trigger other actions #

QR codes can hold more than web links: phone numbers, pre-written text messages, email drafts, Wi-Fi logins, and special links that open other apps. A code could fill in a text to a premium-rate number, or connect you to a Wi-Fi network someone else controls. Each still needs you to confirm, but it’s worth reading what a code wants to do before you tap.

Codes that attack the scanner itself #

In theory, a specially crafted code could exploit a bug in a badly written scanner app. It’s a niche risk, and it’s one reason to use your phone’s built-in camera or a well-maintained scanner, and to keep apps updated.

Can scanning a QR code hack your phone? #

Not by scanning alone. Reading the code decodes text. The realistic attack paths all need one more step from you:

  1. Opening the link.
  2. Typing information into the page.
  3. Installing an app, file or profile.
  4. Granting a permission.

Stop at step 1, read where the link goes, and you’ve avoided nearly all of it.

How to protect yourself #

  1. Read the contents before opening. Look at the full web address and find the real domain.
  2. Don’t install apps from a QR link. The FBI advises getting apps from your phone’s official app store rather than by scanning a code.
  3. Don’t grant permissions to sites or apps you reached through a code, especially accessibility, device admin or profile installs.
  4. Keep your phone updated.
  5. Be suspicious of codes you didn’t expect: stickers on meters, codes in emails and texts, codes in packages you didn’t order.

QR Handler is built around step 1. It never opens a code by itself; every scan goes to a result screen showing the full contents. For links it names the real host and flags plain http, shortened links, raw IP addresses, addresses that hide the real site behind an @, and look-alike characters. It only opens web, email, phone and text-message links, and refuses other link types outright. It doesn’t scan pages for malware or check links against a blocklist, so a malicious site with an ordinary name won’t be flagged. It gives you a clear look at the address, and you make the decision. Our guide to checking a QR code before opening it covers what to look for.

Signs your phone may have picked something up #

If you opened a suspicious code and then installed or allowed something, watch for:

  • Apps you don’t remember installing.
  • A configuration profile or device management entry you didn’t add (on iPhone, look in Settings > General).
  • Apps with accessibility or device admin access that shouldn’t have it (on Android).
  • Pop-ups outside the browser, or your home screen changing.
  • Battery drain or data use you can’t explain.

If you see any of these, remove the app or profile, run Google Play Protect on Android, change your important passwords, and follow our steps for what to do after scanning a malicious QR code.

Frequently asked questions #

Can a QR code install an app automatically? #

No. A QR code can link to a download page, but installing still takes your action and, on iPhone, the App Store. On Android, installing from outside Google Play also requires you to allow it.

Can a QR code steal my data just by scanning? #

No. Scanning only reads the code. Data is stolen when you type it into a page you opened, or install something that collects it.

Yes. Reading the code and looking at the address is safe. Just don’t open, install or sign in to anything you’re unsure about.

Do antivirus apps protect against QR code malware? #

Security apps and browser warnings can block sites and apps already known to be malicious. They may miss brand-new ones, so reading the address and refusing unexpected downloads still matters.