Amazon fixes security flaw in Kindle ebooks
The flaw could have allowed hackers to access your Amazon account details


Amazon has responded to complaints about malware present on Kindle ebooks by fixing the security flaw.
Yesterday, it was revealed that some ebooks downloaded from the internet were installing malware on the ereader, meaning hackers could potentially gain access to users' Amazon accounts or personal details for identity fraud purposes.
Security researcher Benjamin Daniel Mussler uncovered the flaw and said Amazon was very much open to a cross-site scripting attack.
The issue is not thought to affect people who buy their books from Amazon, but could arise if they use an illegal download or untrustworthy ebook site.
The problem begins when a hacker embeds a malicious script into the ebook file, or simply hyperlinks to the script in its download link.
If you find a book you've been desperately looking for on an ebook download website (for example, an illegal download site), download it and then email it to your Kindle using the Send to Kindle feature, it will show up in your Kindle library on Amazon's website as a script file (typically with a subject that includes
The script could allow everything a user does on their Kindle to be tracked, so if people head back to the Amazon Kindle store and re-login, the hacker would have their login details.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
This flaw does not affect books from Amazon itself, so Mussler's advice is to only download ebooks from Amazon or other trustworthy sites.
Mussler first discovered the flaw in 2013, but Amazon fixed it in three weeks. He then-rediscovered it in July and Amazon failed to patch it, hence why he wrote about it on his blog.

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
Intune flaw pushed Windows 11 upgrades on blocked devices
News Microsoft is working on a solution after Intune upgraded devices contrary to policies
By Nicole Kobie
-
Asus ZenScreen Fold OLED MQ17QH review
Reviews A stunning foldable 17.3in OLED display – but it's too expensive to be anything more than a thrilling tech demo
By Sasha Muller
-
‘If you want to look like a flesh-bound chatbot, then by all means use an AI teleprompter’: Amazon banned candidates from using AI tools during interviews – here’s why you should never use them to secure a job
News Amazon has banned the use of AI tools during the interview process – and it’s not the only major firm cracking down on the trend.
By George Fitzmaurice
-
Amazon's RTO mandate could spark a talent exodus
News A survey of Amazon staff suggests plenty remain unhappy about returning to the office next year
By Nicole Kobie
-
Amazon's RTO mandate just hit a major roadblock – it doesn’t have enough office space
News The company has told staff in several locations that it won't have room for them all in time
By Emma Woollacott
-
“There are other companies around”: AWS CEO Matt Garman says employees pushing back on RTO mandates should quit
News AWS CEO Matt Garman says employees pushing back on RTO mandates should quit
By Nicole Kobie
-
Business execs just said the quiet part out loud on RTO mandates — A quarter admit forcing staff back into the office was meant to make them quit
News Companies know staff don't want to go back to the office, and that may be part of their plan with RTO mandates
By Nicole Kobie
-
Microsoft tells staff it won’t follow Amazon or Dell on enforcing a return to the office – but there’s a catch
News While other big tech companies are forcing reluctant workforces back into the office, Microsoft isn’t following suit
By George Fitzmaurice
-
Amazon workers aren’t happy with the company’s controversial RTO scheme – and they’re making their voices heard
News An internal staff survey at Amazon shows many workers are unhappy about the prospect of a full return to the office
By Ross Kelly
-
Amazon set a goal to reach 100% renewable energy by 2030 – it reached it seven years early
News The tech giant has rapidly accelerated renewable energy investment in recent years
By Ross Kelly