Does encoding URLs in QR codes expose the scanners to quishing[0] attacks, such as bad actors sticking malicious QR codes over legit ones?
[0]: https://en.wikipedia.org/wiki/Phishing#QR_code_phishing_(qui...
Yes, but it's no different from the QR codes already present on many consumer products. In fact, it is easier to spot, as either a cashier (or someone at a self-checkout) is likely to notice that there's a sticker over the barcode and get suspicious that there's some kind of fraud going on.
The standard URL format can also be encoded into RFID tags.
This is likely where things will head as printing serialized products is slow, cumbersome and is fraught with issues due to smearing, resolution etc.. and the reason you mentioned.