Vatican Prayer App Click to Pray Leaks 700,000 User Emails
Security researcher BobDaHacker found that the Vatican's Click to Pray app exposed all users' names and email addresses via an API endpoint. The vulnerability went unreported for over six months after being disclosed, and was only fixed after the issue was published. The app has around 720,000 accounts.