Amazon Kindle Library Flaw Exposes User Cookies: Report

Advertisement
By Robin Sinha | Updated: 16 September 2014 18:47 IST

Amazon's 'Manage Your Kindle' page has been reportedly spotted with a flaw that could give hackers access to the user's cookies.

According to a user named Benjamin Daniel Musserl who discovered the bug, if users load a corrupted e-book featuring malicious scripts in their Kindle library, by either downloading and importing, or tapping 'Send to Kindle' from a untrustworthy website, hackers can get access to the user account's cookies.

Notably, corrupted e-books that are said to give access to a user's Amazon account cookies include scripts in their title, such as .

Advertisement

"Once an attacker manages to have an e-book (file, document, ...) with a title like added to the victim's library, the code will be executed as soon as the victim opens the Kindle Library web page. As a result, Amazon account cookies can be accessed by and transferred to the attacker and the victim's Amazon account can be compromised," stated Musserl on a blog post.

In addition, Musserl said that he discovered the bug back in October last year, but Amazon patched it soon after. However, the bug started showing again after Amazon introduced an overhauled 'Manage Your Kindle' section.

Users can however avoid the bug by simply not importing e-books from any other website except Amazon, or other trustworthy sources. The company is yet to make an official comment on the issue.

Advertisement

In July, Amazon announced the launch of a Kindle Unlimited ebooks and audiobooks subscription service. For $9.99 (roughly Rs. 610) a month, customers can read from over 600,000 Kindle books, and listen to thousands of Audible audiobooks, 'keeping' individual titles for as long as they want.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week (Sept 28 - Oct 5): Madharaasi, Junior, Annapoorani, and More
  1. Engineers Create First Artificial Neurons With Electrical Functions As Living Cells
  2. A Better Metric Might Assess The Habitability of Exoplanets: What You Need to Know
  3. SpaceX Prepares for October 13 Launch of Starship Flight 11, Final Test of Current Variant
  4. Jamnapaar Season 2 OTT Release Revealed: When and Where to Watch the Season 2 Online?
  5. Kurukshetra OTT Release Date Announced: Know When and Where to Watch it Online?
  6. BNB Chain’s X Account Hacked; CZ Warns Users of Phishing Links
  7. People We Meet on Vacations OTT Release Date: Know When and Where to Watch it Online?
  8. My Hero Academia Final Season OTT Release Date: When and Where to Watch it Online?
  9. James Webb Offers First Glimpse Into How Moons Are Built Around Distant Planets
  10. James Webb Telescope Unveils Hidden Star-Forming Regions in Sagittarius B2
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.