Trending

Stories

Hackers Might Exploit Bug in Amazon Kindle and Company Issues Fix

Must Read

A team of cyber-security researchers has discovered security flaws in the popular e-reading device Amazon Kindle that might have led hackers to take full control of a Kindle device, opening a path to stealing information stored.

By tricking victims into opening a malicious e-book, a threat actor could have leveraged the flaws to target specific demographics and take full control of a Kindle device, according to a Check Point Research (CPR) team.

Also Read

The researchers disclosed their findings to Amazon, and the company deployed a fix via a Kindle’s firmware update in April this year. The patched firmware installs automatically on devices connected to the Internet.

“By sending Kindle users a single malicious e-book, a threat actor could have stolen any information stored on the device, from Amazon account credentials to billing information,” said Yaniv Balmas, Head of Cyber Research at Check Point Software.

Kindle, like other IoT devices, are often thought of as innocuous and disregarded as security risks.

“But our research demonstrates that any electronic device, at the end of the day, is some form of computer. And as such, these IoT devices are vulnerable to the same attacks as computers,” he added.

The exploitation involves sending a malicious e-book to a victim.

Once the e-book is delivered, the victim simply needs to open it to start the exploit chain.

No other indication or interactions are required on behalf of the victim to execute the exploitation.

The team proved that an e-book could have been used as malware against Kindle, leading to a range of consequences.

For example, an attacker could delete a user’s e-books, or convert the Kindle into a malicious bot, enabling them to attack other devices in the user’s local network.

“Amazon was cooperative throughout our coordinated disclosure process, and we’re glad they deployed a patch for these security issues,” the CPR team noted.

Stay updated

Subscribe to our newsletter and never miss an update on the latest tech, gaming, startup, how to guide, deals and more.

Latest

Stories

- Advertisement -
- Advertisement -

Latest

Grow Your Business

Place your brand in front of tech-savvy audience. Partner with us to build brand awareness, increase website traffic, generate qualified leads, and grow your business.

- Advertisement -

Related

- Advertisement -
- Advertisement -
Nothing Phone (2) Confirmed for India Production Fitbit Integration with Google Accounts Begins Xiaomi 13 Ultra Global Launch: Offers, Price, Specs Meta Unveils Quest 3 VR Headset, Reduces Price for Quest 2 Foxconn to Manufacture iPhones in Karnataka, India: Creating 50,000 Jobs Amazon Echo Pop: Stylish Semi-Sphere Smart Speaker in India Redmi Display A27: Affordable 27 Inches Monitor with 100Hz Refresh Apple Music Classical App Now Available on Android WhatsApp’s Companion Mode: Same Account, Multiple Devices Nvidia & MediaTek Collaborate on Connected Car Tech
Nothing Phone (2) Confirmed for India Production Fitbit Integration with Google Accounts Begins Xiaomi 13 Ultra Global Launch: Offers, Price, Specs Meta Unveils Quest 3 VR Headset, Reduces Price for Quest 2 Foxconn to Manufacture iPhones in Karnataka, India: Creating 50,000 Jobs Amazon Echo Pop: Stylish Semi-Sphere Smart Speaker in India Redmi Display A27: Affordable 27 Inches Monitor with 100Hz Refresh Apple Music Classical App Now Available on Android