Hacking Android Smartphones with NFC Tags
arxiv.org
arxiv.org
1. Scanning a QR tag and going to the URL requires the user to open a QR reading app at minimum. NFC scanning runs in the background.
2. QR codes are visible to humans, whereas you can put an NFC tag in anything, and can spoof it from at least centimeters away.
3. The contact info vulnerability, which isn't just opening a URL, seems really bad, as it adds stuff to your contacts without asking.