Improper Certificate Validation in Kura Sushi Official App for Android and Kura Sushi Official App for iOS - CVE-2026-41872
Published: May 11, 2026
Vulnerability identifier: #VU130920
CSH Severity: High
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41872
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper certificate validation on push notifications. A remote attacker can perform a man-in-the-middle (MitM) attack and eavesdrop or alter the communication on push notifications.
Affected software
Kura Sushi Official App for Android
Kura Sushi Official App for iOS
Kura Sushi Official App for iOS
How to mitigate CVE-2026-41872
Install updates from vendor's website.
Kura Sushi Official App for Android - update to 3.9.11
Kura Sushi Official App for iOS - update to 3.9.11
Kura Sushi Official App for iOS - update to 3.9.11