Pope’s official prayer app commits cardinal sin, leaks 700K+ users’ info
Click To Pray, the Pope-endorsed prayer app, reportedly exposed the personal information of more than 719,000 registered users through a basic security flaw that had allegedly been reported six months earlier without a response. The issue matters because the data could enable convincing phishing attempts aimed at users who may place particular trust in Vatican-branded communications.
A researcher said the app’s API allowed anyone to retrieve records for any valid sequential five-digit user ID without checking authorisation, exposing names, email addresses, countries, dates of birth and account-status information. The app reportedly had 719,517 accounts in July 2026, and the lack of rate limiting meant all could potentially be enumerated; a separate sign-up flaw also exposed email-verification tokens, potentially allowing accounts registered with another person’s email address to be verified.
- Prayer app allegedly exposed data from 719,517 accounts.
- A simple API flaw reportedly allowed mass data scraping.
- Exposed details could support targeted Vatican-themed phishing.