Pope’s Click To Pray app exposed data for more than 719,000 users through an API authorization flaw

The Vatican-backed Click To Pray app exposed personal data tied to more than 719,000 user accounts, potentially putting users at risk of phishing and account abuse. A researcher says an insecure direct object reference (IDOR) flaw in the app’s API let anyone enumerate sequential user IDs and retrieve names, email addresses, countries, birth dates, and account status, while the sign-up flow also returned the email-verification token directly in the response.
Why it matters: This affects a large global user base, including many potentially vulnerable non-technical users who could now be targeted with convincing scam or phishing emails. Users should be cautious of messages claiming to come from the Vatican or the app, and the operator should urgently fix the API, invalidate exposed verification tokens, and review whether data was accessed.

Sources

Pope's official prayer app commits cardinal sin, leaks 700K+ users' info
2026.07.24 100% relevant
This article appears to be the first major report establishing the underlying event: a live API flaw and user-data exposure in the Pope’s official prayer app.
← Back to all stories