Security flaw in Vatican's 'Click to Pray' app exposes over 700,000 users for six months
A security researcher, BobDaHacker, discovered that the Vatican-linked 'Click to Pray' app had zero authentication and security, allowing anyone to access its backend via an API endpoint by simply typing user IDs. The vulnerability exposed user data including first and last names, email addresses, and birthdates. The researcher emailed nine individuals about the flaw in January 2026 but received no response for six months. The app's user IDs were sequential with no rate limiting, enabling automated data harvesting. With nearly 720,000 accounts, mostly older, less tech-savvy users, the leak posed a significant phishing risk. The issue was only fixed after security journalist Nate Nelson of Dark Reading published a story about it. The developers did not acknowledge the researcher's efforts.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection