Facts
- Noted
- leaked 700,000 user emails · 2026-08-09
- Noted
- exposed all users' names and email addresses via an API endpoint · 2026-08-09
- Noted
- vulnerability went unreported for over six months after being disclosed · 2026-08-09
- Noted
- was only fixed after the issue was published · 2026-08-09
- Noted
- has around 720,000 accounts · 2026-08-09
- Noted
- user base likely includes many elderly non-tech-savvy individuals · 2026-08-09
- Noted
- leaked email addresses are a valuable target for scammers · 2026-08-09
- Noted
- developer's six-month silence raises questions about its security response · 2026-08-09
Structured graph also available as JSON at /public/entities/click-to-pray.
CC BY 4.0.
Aug 9
Security researcher BobDaHacker found that the Vatican's Click to Pray app exposed all users' names and email addresses via an API endpoint. The vulnerability went unreported for over six months after being disclosed, and was only fixed after the issue was published. The app has around 720,000 accounts.