Pope’s official prayer app leaked over 700,000 users’ data for months

The Pope’s official prayer app left more than 700,000 users’ personal details exposed for months, and nobody at the Vatican wrote back for six months.

Click To Pray is the official app of the Pope’s Worldwide Prayer Network, and it connects Catholics across the globe to pray for Pope Leo XIV’s own daily intentions. Naturally, that kind of endorsement draws over 719,000 accounts, and skews older and devoutly unsuspicious, exactly the crowd a security hole like this one was bound to find first.

The bug that let anyone scrape 700,000 accounts

Cybersecurity researcher BobDaHacker, previously known for exposing a free food loophole at McDonald’s, found the hole back in January and reported it straight to the app’s operators.

The flaw stayed live for six months until security outlet Dark Reading independently verified it and published its own report. The endpoint was quietly restricted days later, though nobody at the Pope’s Worldwide Prayer Network ever acknowledged BobDaHacker for finding it.

Click to Pray

The bug was called an IDOR, tech shorthand for a system that had handed over data to anyone who asked, without ever checking whether they were allowed to have it.

If you asked for your own account, the app would hand it over, no surprises there. But if you changed one number in the web address and asked for someone else’s, it would hand that over too, without asking for a login, verification, or any other steps. That single flaw was enough to let anyone quietly work through the entire user base and scoop up names, emails, countries and birthdates along the way.

On top of that, the signup process handed back the exact verification code needed to confirm a new account, so anyone could’ve registered under someone else’s email and confirmed it before the real message ever arrived. Combine that with a user base that skewed elderly and trusted anything wearing a Vatican seal, and the phishing potential turned grim fast.

As BobDaHacker put it, “Grandma is clicking that. Every time.” Despite going public with the flaw and reaching out for months, the bug stayed live until late July 2026, when it was quietly patched, with no acknowledgment ever sent to BobDaHacker.

None of this is new, either. One YouTuber found himself in a similar spot last year, when a security researcher hacked into his new translation app to expose its flaws rather than wait for the company to notice on its own.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *