Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Pope's Official Prayer App Leaks 700K+ Users' Personal Information: A Security Breach of Unprecedented Proportions


The Pope's official prayer app has leaked the personal information of over 700,000 users, exposing them to potential phishing attacks. The app's developer has yet to respond to reports of the vulnerability, leaving many users feeling vulnerable and exposed.

  • The Pope's official prayer app, Click To Pray, has leaked the personal information of over 700,000 users due to an Insecure Direct Object Reference (IDOR) bug.
  • The bug allows anyone to access other users' personal data by providing a valid five-digit user ID.
  • Many vulnerable users are likely older individuals who may not be tech-savvy or familiar with online security measures.
  • The lack of proper verification procedures makes it easy for attackers to launch phishing campaigns, using the leaked information to trick users into revealing sensitive data.
  • The Pope's Worldwide Prayer Network has not responded to a report about the vulnerability and has left the app available for download.


  • The Pope's official prayer app, Click To Pray, has been embroiled in a scandal of epic proportions after it was discovered that the app had leaked the personal information of over 700,000 users. The breach, which is believed to have occurred for months or even longer, has left many users feeling vulnerable and exposed.

    The app, which is available on iOS, Android, and the clicktopray.org website, was endorsed by the Pope's Worldwide Prayer Network and was intended to connect users across the globe with the Holy Father's intentions. However, according to security sleuth BobDaHacker, the app contains a devastating Insecure Direct Object Reference (IDOR) bug that allows anyone to access the personal information of other users.

    The bug, which is a common type of flaw that occurs when a website or app blindly accepts user-provided input without checking to see if the user is authorized to retrieve the data, was discovered by BobDaHacker in January 2026. Despite reporting the vulnerability to the Pope's Worldwide Prayer Network six months ago, she claims that her email was met with complete silence.

    "This is a very common and easy-to-exploit type of flaw," BobDaHacker explained. "You ask for your own data, the server gives it to you. You ask for someone else's data, the server gives you that too. Thou shalt not authorize, apparently." The bug allows an attacker to access any user's information by simply providing a valid, five-digit user ID.

    The leaked information includes users' email addresses, first and last names, country, dates of birth, and whether the account has been deleted. BobDaHacker estimates that many of these users are likely older individuals who may not be tech-savvy or familiar with online security measures.

    "This is a phishing goldmine," she noted. "Imagine getting an email that says 'The Holy Father requests your urgent attention' with a Vatican-looking link. Grandma is clicking that. Every time." The lack of proper verification procedures and the exposure of user data make it easy for attackers to launch successful phishing campaigns.

    Furthermore, BobDaHacker discovered that the signup endpoint for the app returns the account's validation hash directly in the response body. This means that someone could sign up using any email address and verify the account before the confirmation message reached the inbox. This raises serious concerns about the security of the entire platform.

    The Pope's Worldwide Prayer Network has yet to respond to BobDaHacker's report or take steps to rectify the situation. The app remains available for download, with over 700,000 users potentially exposed to this vulnerability.

    In conclusion, the breach of Click To Pray is a stark reminder of the importance of robust online security measures and the need for developers to prioritize user safety above all else.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/Popes-Official-Prayer-App-Leaks-700K-Users-Personal-Information-A-Security-Breach-of-Unprecedented-Proportions-ehn.shtml

  • https://www.theregister.com/security/2026/07/24/popes-official-prayer-app-commits-cardinal-sin-leaks-700k-users-info/5278603

  • https://san.com/cc/the-popes-prayer-app-has-been-leaking-its-users-info-for-months/


  • Published: Fri Jul 24 17:56:45 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us