Switch language한국어
Back to the list

Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been leaking user data for over six months and still does

TL;DR AI

Key summary

2 min read
  1. Click To Pray, a Vatican-linked prayer app, exposed user data through an insecure API that allowed access via sequential user IDs.

  2. The leak included names, email addresses, and birthdates for hundreds of thousands of users, with little protection such as rate limiting.

  3. A security researcher reported the flaw in January 2026, but the operators did not respond for months.

  4. After public reporting by a journalist, the vulnerability was patched.

Read the original