Vatican's 'Click To Pray' App Exposed User Data, Prompting Security Fix
The Vatican's 'Click To Pray' app, promoted by Pope Francis, was found to have significant security vulnerabilities that exposed the personal data of over 700,000 users. The app, which encourages users to join in prayer with the Pope, was discovered to have a flaw that allowed unauthorized access to user information such as email addresses, names, and other personal details. This issue was highlighted by a white-hat hacker known as BobDaHacker, who revealed the vulnerability in a blog post. The flaw allowed anyone to access user data by simply incrementing user ID numbers in the app's API. Despite attempts to alert the Vatican and app developers since January, the issue was only addressed after the hacker went public with the findings.