Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: Win an ADATA SE880 2TB Portable External SSD

Pope's official prayer app exposed data of more than 700,000 users

The Pope's official prayer app left 700,000 users exposed for months, with the flaw exposing full access to names, emails, and more sensitive user data.

Pope's official prayer app exposed data of more than 700,000 users
Comments
Tech and Science Editor
Published
1-minute read time
TL;DR: The Vatican-endorsed Click To Pray app exposed over 700,000 users' personal data for six months via an IDOR flaw that revealed names, emails, birthdates and locations and allowed account takeover; researcher BobDaHacker reported it in January 2026 but received no response before it was quietly fixed in July 2026.
Voice: Jak Connor
0:00 / 1:59
Use left and right arrow keys to seek audio.

The Pope's official prayer app leaked the personal data of over 700,000 users for months, with the Vatican offering no response to the ethical hacker who first reported the flaw.

Pope's official prayer app exposed data of more than 700,000 users 1

The app, Click To Pray, is the Vatican-endorsed prayer app that attracted more than 700,000 users who are connected the global prayer network. However, Cybersecurity researcher BobDaHacker discovered a flaw in January 2026 and reported it directly to the app's operators. For six months, the bug remained unpatched, allowing anyone to access any user's data simply by altering a number in the URL. The vulnerability also let attackers register and confirm accounts using someone else's email, further increasing the risk of phishing and identity theft.

The user base, skewed toward elderly and devout Catholics, made the breach particularly dangerous. As BobDaHacker noted, "Grandma is clicking that. Every time," referencing how a bad actor could take the information from one of the elderly users and craft a phishing scam by posing as the app in some regard. The flaw was found to expose names, emails, birthdates, and locations due to a severe IDOR vulnerability, but it was quietly patched in late July 2026. However, the Vatican never acknowledged the researcher who originally discovered it, or the exposed users.

Frequently Asked Questions

TweakBot answers common questions about this news using TweakTown's own coverage from this page and related content from our archive. Tap a question to reveal the answer, or type your own below.

Question #1

When was the vulnerability patched and did the Vatican publicly acknowledge the breach?

Question #2

What specific risks (for example phishing or identity theft) did researchers warn about?

Have a question not listed here? Ask below and TweakBot will answer it.

With no sign of a public response or accountability, the incident raises serious concerns about data protection in religious and institutional apps, and the lack of repercussions for violations of regulations. I suppose we can only pray that the hundreds of thousands of users that had their data exposed aren't now targeted

Photo of the How To Pray The Rosary Chart Poster

Best Deals: How To Pray The Rosary Chart Poster

* Prices may be inaccurate. As an Amazon Associate, we earn from qualifying purchases. We earn affiliate commission from any Newegg or PCCG sales.

News Source:dexerto.com

Comments

Tech and Science Editor

Email IconX IconLinkedIn Icon

Jak joined TweakTown in 2017 and has since reviewed 100s of new tech products and kept us informed daily on the latest science, space, and artificial intelligence news. Jak's love for science, space, and technology, and, more specifically, PC gaming, began at 10 years old. It was the day his dad showed him how to play Age of Empires on an old Compaq PC. Ever since that day, Jak fell in love with games and the progression of the technology industry in all its forms.

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News
Newsletter Subscription