The pope’s prayer app has been leaking its users’ info for months

July 24, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: san.com

Threat Risk: Medium
Victim: Click To Pray app users
Incident: An IDOR vulnerability exposed the personal information of approximately 720,000 users.
Impact: High risk of targeted phishing attacks leveraging the users’ trust in the Vatican.
Attacker: Unidentified threat actors
Analysis: The exposure stems from an Insecure Direct Object Reference (IDOR) vulnerability, allowing anyone to iterate user IDs to harvest data. The leaked information includes names, emails, and locations, creating a prime target for highly targeted phishing campaigns. The vulnerability has reportedly persisted for over six months despite researcher notifications.
Recommendations: Implement strict server-side access controls to prevent IDOR vulnerabilities; Notify all affected users of the data exposure; Conduct a comprehensive security audit of all API endpoints
Source: Straight Arrow / Dark Reading

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *