Couldn't any exploit possible via that pathway also be executed based on a link? I don't see how a QR code makes the situation any worse.
Once users are habituated to scanning QR codes for verification, it becomes easier.
Once users are habituated to scanning QR codes for verification, it becomes easier.