Heres thr gist I got from it:
Scammer buys sponsored link, link has extra bits on URL.
Website operator's page loads, but blindly accepts extra info from the clicked URL (for prefilled search terms) and displays that in their own search bar's text input field.
The Apple and HP examples show this decently, the scammer text/phone number is just sitting as search input.
Blame whoever, but seems like this is on the website operators/developers as much as $boogeyManSearchEngine.
Heres thr gist I got from it: Scammer buys sponsored link, link has extra bits on URL.
Website operator's page loads, but blindly accepts extra info from the clicked URL (for prefilled search terms) and displays that in their own search bar's text input field.
The Apple and HP examples show this decently, the scammer text/phone number is just sitting as search input.
Blame whoever, but seems like this is on the website operators/developers as much as $boogeyManSearchEngine.