> Access to the device's camera was also gained
Again, that's impossible without an explicit notification on your phone requesting camera access. All of these would be fairly obvious to the user, assuming they even go as far as installing your app. By default you can't even install apps not from the play store without going through a couple step, which I highly doubt average users would.
It’s also a LONG way from:
>"As soon as I scanned the QR code, a sum of Rs 32,000 was withdrawn from my account. Then the caller switched off his phone and was unreachable thereafter,"
The article is mostly BS I’m pretty sure. A bunch of possible but not plausible Android hacking anecdotes that may or may not have happened that mislead by pretending this is a QR or restaurant problem.
It has the access you give it, but the article shows an example leaving every permission allowed. So the QR code really does seem immaterial here.