Smashing Security

The Kindle that got pwned

19 snips
Dec 18, 2025
Join technology journalist Danny Palmer as he delves into the surprising vulnerabilities of Kindle e-readers. He reveals how a seemingly innocuous audiobook could lead to account takeovers and credit card theft through exploitable flaws. The discussion also includes a recap of the notorious ransomware attack on Ireland’s Health Service Executive, exploring its lasting impacts and the recent compensation offered to victims. Plus, enjoy holiday film and game picks that celebrate nostalgia and warmth!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Kindles Are IoT Computers

  • Kindles are full-fledged IoT computers that run Linux and process many file types behind the scenes.
  • Hidden background parsing of files (like audiobooks) creates attack surfaces most users never consider.
ADVICE

Treat E-Readers Like Computers

  • Treat e-readers as devices that need security attention and updates, not mere appliances.
  • Keep firmware updated and be cautious about content sources even if they appear official.
INSIGHT

Audiobook Metadata Can Hide Exploits

  • Amazon's audiobook parser dug deep into metadata and had a textbook heap overflow vulnerability.
  • That flaw could allow crafted audiobooks to overwrite memory and execute attacker code on Kindles.
Get the Snipd Podcast app to discover more snips from this episode
Get the app