Anime, manga, and games, with a take · A Yukimedia publication

← all stories other 1 sources · 1h ago ·

Vatican Prayer App Click to Pray Leaks 700,000 User Emails

The app's user base, likely including many elderly non-tech-savvy individuals, makes the leaked email addresses a valuable target for scammers, and the developer's six-month silence raises questions about its security response.

Reporting from 1 source: GIGAZINE.

Vatican Prayer App Click to Pray Leaks 700,000 User Emails

Security researcher BobDaHacker found that the Vatican's Click to Pray app exposed all users' names and email addresses via an API endpoint. The vulnerability went unreported for over six months after being disclosed, and was only fixed after the issue was published. The app has around 720,000 accounts.

The Vatican's official prayer app Click to Pray had a security flaw that let anyone access user data by entering a user ID at an API endpoint. The exposed information included first and last names, email addresses, and birth dates.

Researcher BobDaHacker found that user IDs were sequential and the API had no rate limit, so a single GET request per user could collect the entire database. The validation_hash used to confirm account registration was stored in plain text, allowing anyone with API access to authenticate accounts. Even the emails sent by the app looked like phishing messages.

BobDaHacker reported the issue by email but received no response for over six months. The problem was fixed only after the story was published, and the developer never thanked or acknowledged the researcher.

Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources