Exclusive Student Offer

Prime for Young Adults

Get a 6-month trial with premium college perks & fast delivery.

Start Free Trial
Listen Anywhere

Audible Standard Trial

Get 30 days of audiobooks free. Cancel anytime, keep your books.

Claim Free Books

The official prayer app of the Pope, intended to connect believers around the globe, has recently made headlines for all the wrong reasons. Security vulnerabilities have exposed personal information of over 700,000 users, raising significant concerns about data privacy and security management within the application.

Image: Canva

Launched in 2019, the Click to Pray app allows users to connect and pray collectively in seven different languages. However, instead of fostering a sense of community, recent discoveries have painted a troubling picture about the app’s security measures.

Multiple Security Vulnerabilities Found

In January 2026, security researcher known as BobDaHacker identified several critical security flaws. An especially alarming issue was the presence of an unprotected API that allowed unauthorized access to personal data of over 700,000 users without the need for authentication. Additionally, shortcomings were found in the account registration process.

Personal Data Was Exposed

The core issue centered around the unprotected API, where access seemed to require only a user ID, with no further authentication measures in place. Because these user IDs are sequentially assigned, attackers could automate the process and potentially infiltrate every user account. Exposed data included first and last names, email addresses, birth dates, and user roles. In some cases, even geographical details and account status were reportedly accessible.

According to BobDaHacker, such sensitive information could be exploited for targeted phishing attacks. The risk is particularly pronounced given that many app users may be older or less technologically proficient, making them prime targets.

Additional Weaknesses Compounded the Issue

Beyond the API vulnerability, BobDaHacker also discovered additional flaws. The email verification process could be bypassed because the required confirmation code was retrievable via the API. This meant that attackers could register and validate accounts using email addresses they didn’t control.

Furthermore, issues with the authentication of emails sent by the app also came to light. Many email systems flagged messages as potentially fraudulent, complicating users’ ability to distinguish between legitimate and fake communications, thus increasing the likelihood of successful phishing attempts.

Delayed Response from Operators

BobDaHacker reported these vulnerabilities on January 3, 2026, contacting nine different staff members associated with Click to Pray and the Pope’s prayer network. Disturbingly, she received no response for over six months.

It wasn’t until the security portal Dark Reading brought the issue to public attention on July 24, 2026, that the app’s operators seemingly took action, closing the vulnerabilities. However, no official confirmation or acknowledgment has been provided to date, and BobDaHacker has yet to receive feedback on her initial report.


Whether the exposed data has been misused or whether affected users have been informed remains unclear. Given the size and intention of the platform, a swifter response and more transparent communication from the operators would have been appreciated.


Note: We rely on your support to continue our work. If you find value in what we do, consider marking us as a preferred source on Google and following us on Google News. Every bit of support helps!


Source: Golem/t3n

Get Audible 30-Day Free Trial

As an Amazon Associate, we earn from qualifying purchases.