Begin typing your search above and press return to search.
proflie-avatar
Login
exit_to_app
DEEP READ
Ukraine
access_time 16 Aug 2023 11:16 AM IST
Espionage in the UK
access_time 13 Jun 2025 10:20 PM IST
Yet another air tragedy
access_time 13 Jun 2025 9:45 AM IST
exit_to_app
Homechevron_rightTechnologychevron_rightAmazon Kindle's bug...

Amazon Kindle's bug could let hackers take control of your ebook reader and steal information

text_fields
bookmark_border
Amazon Kindles bug could let hackers take control of your ebook reader and steal information
cancel

New Delhi: A team of cyber-security researchers has discovered a critical vulnerability in the popular e-reading device Kindle that could be potentially exploited to take full control over a user's device, resulting in the theft of sensitive information.

According to a CheckPoint Research (CPR) team, a threat actor could trick the victims into opening a malicious ebook and leverage the flaws to target specific demographics and take full control of a Kindle device.

The researchers disclosed their findings to Amazon and the company deployed a fix via a Kindle's firmware update in April this year. The patched firmware installs automatically on devices connected to the Internet.

"By sending Kindle users a single malicious e-book, a threat actor could have stolen any information stored on the device, from Amazon account credentials to billing information," said Yaniv Balmas, Head of Cyber Research at Check Point Software.

Kindle, like other IoT devices, are often thought of as innocuous and disregarded as security risks.

"But our research demonstrates that any electronic device, at the end of the day, is some form of computer. And as such, these IoT devices are vulnerable to the same attacks as computers," he added.

The exploitation involves sending a malicious e-book to a victim.

Once the e-book is delivered, the victim simply needs to open it to start the exploit chain.

No other indication or interactions are required on behalf of the victim to execute the exploitation.

The team proved that an e-book could have been used as malware against Kindle, leading to a range of consequences.

For example, an attacker could delete a user's e-books, or convert the Kindle into a malicious bot, enabling them to attack other devices in the user's local network.

"Amazon was cooperative throughout our coordinated disclosure process, and we're glad they deployed a patch for these security issues," the CPR team noted.

Show Full Article
TAGS:Amazon kindleEbook reader
Next Story