Vulnerability found in "Kura Sushi Official App"; addressed with a forced update on launch, JVN reports

TL;DR AI
2 min readKey summary
JVN reported a certificate verification weakness in the Kura Sushi official app’s push-notification communication.
The issue affects iOS and Android versions 2.0.11 through 3.9.10.
Kura Sushi has released version 3.9.11, and affected users are forced to update when opening the app.
On the same network, an attacker could potentially intercept or tamper with push-notification traffic.



