Researcher Identified QR Tiger Subdomain Vulnerability
A persistent vulnerability allows attackers to hijack branded web domains via stale DNS records, remaining unpatched five months after reporting.
Updated on Sept. 25, 2026 in Cybersecurity

Live Poll
Do you trust that companies effectively manage your digital security and personal data?
Security researcher Farzan Karimi has disclosed a subdomain hijacking flaw in the QR provider QR Tiger that could expose brands to credential theft and phishing. The vulnerability remains unpatched five months after Karimi initially reported it to the company.
Why it matters
The vulnerability highlights the risks of legacy infrastructure management, as businesses often neglect to prune Domain Name System records after decommissioning services. Attackers can exploit these abandoned pointers to impersonate legitimate brand assets.
The flaw, a variant of QR Jacking, relies on stale CNAME records that continue to point to QR Tiger servers; an attacker can claim an abandoned subdomain in under one minute to hijack the associated URL.
The players
Farzan Karimi
Security researcher who identified the QR Tiger subdomain flaw and developed the scanning tool QR Tiger King.
QR Tiger
A provider of QR code generation software that maintains the custom domain feature affected by the reported vulnerability.
Mohamed Abdelbasset Elnouby
Security researcher who published the original QRLJacking attack methodology in 2016.
The details
Attackers perform the hijacking by claiming a subdomain that a company previously used for QR Tiger services but failed to remove from their DNS, the system that translates domain names into IP addresses. Because the CNAME (Canonical Name) record remains pointed at the platform, the attacker can redirect traffic to a site of their choosing. The mechanism allows for a takeover in under one minute, effectively turning a trusted brand domain into a vehicle for malicious redirects.
Timeline
2016: QRLJacking attack published by Mohamed Abdelbasset Elnouby.
April 2026: Karimi reported the flaw to QR Tiger.
September 2026: Karimi published the QR Jacking research.
The Tech Race
This vulnerability builds upon the 2016 QRLJacking research by identifying modern infrastructure oversights that enable domain takeover. It demonstrates how legacy DNS configurations remain a critical failure point in corporate security stacks.
Organizations should audit their DNS settings to ensure all CNAME records are actively managed and point only to verified services. Failure to remove records for discontinued platforms allows attackers to take control of branded subdomains in less than a minute.
The takeaway
Security teams should prioritize the cleanup of stale DNS pointers to prevent subdomain takeovers that turn trusted links into security threats. Watch for the public release of the QR Tiger King tool on GitHub as an indicator of whether other researchers begin wider exploitation of the flaw.
What happens next
Karimi plans to release his automated scanning tool, QR Tiger King, on GitHub.
Further reading
For more on managing enterprise-level domain risks, explore our deep dive into Cybersecurity.
Source note: This article includes information reported by ITnews.
Live Poll
Do you trust that companies effectively manage your digital security and personal data?






