Kura Sushi Official App Improper Certificate Validation Vulnerability
Vulnerability
A vulnerability exists in the Kura Sushi Official App by EPG, Inc., due to improper validation of certificates. This flaw can lead to a man-in-the-middle attack, where an attacker could intercept or modify push notification communications between the app and its server. The vulnerability is present in the iOS version 2.0.11 prior to 3.9.10 and in the Android version 2.0.11 prior to 3.9.10.
Impact
Exploitation of this vulnerability could allow eavesdropping on or alteration of push notification communications between the app and the server.
Remediation
Users are advised to update the Kura Sushi Official App to version 3.9.11, available on the App Store and Google Play.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
