Story perspectives
Kindle Vulnerabilities Exposed: $20K Bug Bounty Awarded
12/16/2025
1 of 1
Story summary
- A security demonstration at Black Hat Europe revealed Kindle vulnerabilities enabling account access without passwords.
- Valentino Ricotta, an engineering analyst, showed the flaws arise from the Kindle’s parsing process and onscreen keyboard.
- The flaws allowed theft of session cookies, granting unauthorized access.
- Amazon fixed the issues with automatic updates and awarded Ricotta a $20,000 bug bounty.
- Users are advised to research authors before downloading ebooks.
