July 30, 2026, 1:33 pm | Read time: 2 minutes
Ironically, the Vatican’s official prayer app has been flagged for serious security vulnerabilities. According to a security researcher using the pseudonym “BobDaHacker,” personal data of more than 719,000 registered users could be accessed relatively easily.
According to a blog post, the affected app was “Click to Pray”, available for Android, iPhone, and as a web app. Through the service, believers can share their prayer intentions and join the pope’s worldwide prayer network.
Simple User IDs Made Data Accessible
The cause of the data breach was reportedly an unprotected API endpoint. According to the researcher, access only required entering a user ID. Since the system assigned these IDs sequentially, data sets could be queried automatically. This made names, email addresses, birth dates, countries of origin, and account status information accessible. For attackers, this posed little challenge.
In addition to the database vulnerability, the expert discovered another issue in the registration process. Although the service sent verification emails, the necessary information for account activation could be retrieved beforehand via an API. This theoretically allowed user accounts to be activated and taken over with foreign email addresses. This is particularly critical because such a vulnerability can facilitate targeted attacks on individual accounts.
Also of interest: How risky is online banking on a smartphone
Response Came Only After Months
According to BobDaHacker, the vulnerabilities were reported to the operators on January 3, 2026. A response was reportedly not received for several months. It was only after the IT portal Dark Reading reported on the incident at the end of July that the security issues were said to have been resolved. Whether the vulnerabilities were actively exploited in the meantime is currently unknown.