Amazon has patched a flaw in the Amazon Photos app which could have allowed an attacker to steal and use a user’s unique access token that verifies their identity across multiple Amazon APIs.
That would give attackers access to a trove of information, since many of these APIs contain personal data, such as names, email addresses, and home addresses.