Ehhh, this is kinda dumb. There isn't a vulnerability in NFC per se, just that you can encode NFC tags with malicious URLs. If the user isn't paying attention, they might get served with a phishing page, or a page that scrapes the user's location. QR codes would have the same vulnerability. This isn't an NFC problem, this is a social engineering problem - don't scan tags you don't trust, just like you shouldn't open up emails you don't trust.