⚡️🙏 NEW - A major security flaw has been found in the Vatican’s official Click to Pray app, potentially exposing the personal information of more than 700,000 users for at least six months.
According to security researcher BobDaHacker, the app’s API suffered from an Insecure Direct Object Reference (IDOR) vulnerability.
Anyone could change a user ID in a web request and access another person’s account details without logging in or permission.
The exposed information included:
- Names
- Email addresses
- Country of origin
- User role and account status
The researcher says there were around 719,500 registered accounts when the flaw was documented.


According to security researcher BobDaHacker, the app’s API suffered from an Insecure Direct Object Reference (IDOR) vulnerability.
Anyone could change a user ID in a web request and access another person’s account details without logging in or permission.
The exposed information included:
- Names
- Email addresses
- Country of origin
- User role and account status
The researcher says there were around 719,500 registered accounts when the flaw was documented.


82❤️2🤡1🤣1