What's Happening?
A security flaw in the Vatican's 'Click to Pray' app has exposed the personal data of over 700,000 users. Discovered by a security researcher known as BobDaHacker, the flaw allows unauthorized access to user data through the app's API. Despite being reported
in January 2026, the issue remained unaddressed for six months, leaving users vulnerable to phishing attacks. The exposed data includes names, email addresses, and birthdates, posing a significant risk to the app's predominantly older user base.
Why It's Important?
The exposure of user data in the 'Click to Pray' app highlights the critical importance of robust security measures in digital applications, especially those handling sensitive personal information. The prolonged period during which the flaw went unaddressed underscores the need for timely responses to security vulnerabilities. This incident serves as a reminder of the potential risks associated with digital platforms and the importance of safeguarding user data to prevent exploitation by cybercriminals.











