Particle.news
Download on the App Store

Pope-Endorsed Click To Pray App Leaked Data of Over 700,000 Users

Simple API flaws let anyone harvest names, emails and birthdates, exposing gaps in Vatican disclosure procedures.

Overview

  • An independent researcher discovered the vulnerability in January 2026 and the app’s API endpoint was quietly patched in late July 2026 after the researcher went public and journalists followed up.
  • One flaw was an Insecure Direct Object Reference where sequential numeric user IDs returned another person’s record without any authorization checks, revealing names, email addresses, country and date of birth.
  • A second flaw returned the account verification hash in API responses, allowing an attacker to register and verify an account with someone else’s email before the real owner received the verification message.
  • The researcher says they reported the issue to nine Vatican and Click To Pray contacts on January 3, 2026 and received no replies over six months, with no public acknowledgement when the problem was fixed.
  • The exposed data and the service’s failed email authentication create a high phishing risk for a largely older, trust-prone user base, and the incident raises questions about oversight, accountability and how Vatican data-protection rules apply to third-party apps.