A security vulnerability in Amazon.com mobile app (which has been patched) allowed attackers to have an unlimited number of attempts to guess a person's password, according to security firm FireEye.
If users enter their password incorrectly 10 times on the Amazon.com, the company requires them to solve a “character puzzle” known as a CAPTCHA (automated computer-generated identification). CAPTCHA is intended to stop automated programs that try to enter different passwords from functioning.
But Amazon.com did not have a CAPTCHA in its mobile app, such as iOS and Android platforms, allowing unlimited password recovery attempts, according to FireEye researchers Min Zheng, Tao Wei and Hui Xue, who published their findings on the FireEye blog. FireEye notified Amazon.com of the bug on Jan. 30, and the company patched it on Feb. 19.

