Vatican's Click to Pray App Exposed 720,000 Users' Data for Over Six Months
A security researcher, BobDaHacker, discovered that the Vatican-linked 'Click to Pray' app had zero authentication on its API, allowing anyone to access user data including names, email addresses, and birthdates by simply entering sequential user IDs. The app, part of the Pope's Worldwide Prayer Network, had nearly 720,000 accounts as of July 2026. The researcher notified nine individuals in January 2026 but received no response for six months. The vulnerability was only fixed after security journalist Nate Nelson of Dark Reading published a story about it. The lack of rate limiting made bulk data extraction trivial, and the validation_hash was stored in plaintext. The researcher expressed concern that older, less tech-savvy users were particularly vulnerable to phishing attacks. No acknowledgment was given to the researcher by the app's developers.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection