The most frustrating thing about them is that many restaurants don't have their own website, and simply host the PDF on some third-party website, often through a URL shortener. So scanning a restaurant's QR code yields an obfuscated link that, when opened, immediately triggers a download of a PDF menu.
That's shady AF from a security perspective, and we should not be normalizing it.