PulseAugur
EN
LIVE 18:56:27

Vatican's 'Click to Pray' app exposed 700K users' data due to security flaw

A significant security vulnerability in the Vatican's 'Click to Pray' app has exposed the personal data of over 700,000 users worldwide. The flaw, discovered by security researcher BobDaHacker in January 2026, allowed unauthorized access to user information including names, email addresses, and birthdates through an unsecured API. Despite attempts to notify the app's developers, no action was taken for six months, leading to the data leak continuing. The vulnerability was only addressed after a journalist from Dark Reading published a story on the issue. AI

IMPACT Minimal direct impact on AI operations; highlights general app security risks.

RANK_REASON The cluster describes a security vulnerability in a specific app, not a core AI release or significant industry-wide event.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

Vatican's 'Click to Pray' app exposed 700K users' data due to security flaw

COVERAGE [2]

  1. Tom's Hardware TIER_1 English(EN) · Jowi Morales ·

    Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been leaking user data for over six months and still does

    An app linked to the Vatican with hundreds of thousands of users was found to have zero authentication and security. That means anyone can access its backend and siphon users' data, including names, email addresses, and birthdates. While the issue has since been resolved, it rema…

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been le… An app linked to the Vatican with hundreds of thousan

    Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been le… An app linked to the Vatican with hundreds of thousands of users was found to have zero authentication and security. That means anyone can access its backend and siphon user…