At least use a privacy-friendly, secure scanner like @SECUSO_Research@xn--baw-joa.social's "QR Scanner", that requires only minimal permissions, and lets you scrutinize the content before any action is taken.
@aral@mastodon.ar.al You're the third person I've seen talking about these today but I've not come across them yet, thankfully. Bet I can guess which instance they're coming from though.