The 'Click to Pray' app, officially linked to the Pope’s Worldwide Prayer Network, was found to have significant security vulnerabilities. A security researcher, BobDaHacker, discovered in January 2026 that the app's API allowed access to user data by simply inputting user IDs. This flaw exposed personal information for over 700,000 users.
The data accessible through the app's database included users' first and last names, email addresses, and birthdates. Additionally, the validation_hash for account signups was stored in clear text, enabling account verification. The sequential nature of user IDs and lack of rate limiting on the API made it possible to automatically collect this information for all users.
BobDaHacker reported these vulnerabilities to nine individuals associated with the app immediately after discovery. However, no responses were received, and no security changes were implemented for six months. The researcher then contacted a security journalist, Nate Neslon, who published a story about the flaws.
The security lapses in the 'Click to Pray' app were only addressed after the news of the vulnerabilities became public. This delay meant that user data remained exposed for an extended period, increasing the risk of phishing attacks, particularly for the app's user base, which is likely to include less tech-savvy individuals.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The official Vatican 'Click to Pray' app had critical security vulnerabilities that exposed personal data of over 700,000 users for more than six months. A security researcher discovered that user IDs could be used to access names, email addresses, and birthdates, and the issues were only fixed after public disclosure.