Security Flaw in Vatican's 'Click to Pray' App Exposes User Data
A significant security flaw has been discovered in the Vatican's 'Click to Pray' app, exposing the personal data of over 700,000 users. The app, which is part of the Pope's Worldwide Prayer Network, was found to have zero security, allowing easy access to user data through its API endpoint. The exposed data includes names, email addresses, and birthdates, which could be exploited for phishing attacks. Despite being informed of the vulnerability in January 2026, the issue remained unaddressed for over six months, raising concerns about the app's security practices.