← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Vatican's 'Click to Pray' app exposed user data for over six months due to security flaws

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Security researcher BobDaHacker found zero security in January 2026.
  • User data including names, emails, and birthdates were accessible via API.
  • Vulnerabilities were unaddressed for six months despite researcher's notifications.
  • Fixes were implemented only after public reporting by a journalist.

Data Exposure in Vatican Prayer App

The 'Click to Pray' app, officially linked to the Pope’s Worldwide Prayer Network, was found to have significant security vulnerabilities. A security researcher, BobDaHacker, discovered in January 2026 that the app's API allowed access to user data by simply inputting user IDs. This flaw exposed personal information for over 700,000 users.

Exposed User Information

The data accessible through the app's database included users' first and last names, email addresses, and birthdates. Additionally, the validation_hash for account signups was stored in clear text, enabling account verification. The sequential nature of user IDs and lack of rate limiting on the API made it possible to automatically collect this information for all users.

Lack of Response to Vulnerability Reports

BobDaHacker reported these vulnerabilities to nine individuals associated with the app immediately after discovery. However, no responses were received, and no security changes were implemented for six months. The researcher then contacted a security journalist, Nate Neslon, who published a story about the flaws.

Post-Disclosure Remediation

The security lapses in the 'Click to Pray' app were only addressed after the news of the vulnerabilities became public. This delay meant that user data remained exposed for an extended period, increasing the risk of phishing attacks, particularly for the app's user base, which is likely to include less tech-savvy individuals.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Aug 16

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The official Vatican 'Click to Pray' app had critical security vulnerabilities that exposed personal data of over 700,000 users for more than six months. A security researcher discovered that user IDs could be used to access names, email addresses, and birthdates, and the issues were only fixed after public disclosure.