This PoC demonstrates credentialed cross-origin data theft from api.audible.com. When hosted on any *.audible.* subdomain, it can read authenticated API responses with the victim's cookies.