Kura Sushi Official App Improper Certificate Validation Vulnerability

Vulnerability

A vulnerability exists in the Kura Sushi Official App by EPG, Inc., due to improper validation of certificates. This flaw can lead to a man-in-the-middle attack, where an attacker could intercept or modify push notification communications between the app and its server. The vulnerability is present in the iOS version 2.0.11 prior to 3.9.10 and in the Android version 2.0.11 prior to 3.9.10.

Impact

Exploitation of this vulnerability could allow eavesdropping on or alteration of push notification communications between the app and the server.

Remediation

Users are advised to update the Kura Sushi Official App to version 3.9.11, available on the App Store and Google Play.

Added: May 12, 2026, 6:19 AM
Updated: May 12, 2026, 6:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
4.5
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.