The official prayer app of the Pope, intended to connect believers around the globe, has recently made headlines for all the wrong reasons. Security vulnerabilities have exposed personal information of over 700,000 users, raising significant concerns about data privacy and security management within the application.
Launched in 2019, the Click to Pray app allows users to connect and pray collectively in seven different languages. However, instead of fostering a sense of community, recent discoveries have painted a troubling picture about the app’s security measures.
Multiple Security Vulnerabilities Found
In January 2026, security researcher known as BobDaHacker identified several critical security flaws. An especially alarming issue was the presence of an unprotected API that allowed unauthorized access to personal data of over 700,000 users without the need for authentication. Additionally, shortcomings were found in the account registration process.
Personal Data Was Exposed
The core issue centered around the unprotected API, where access seemed to require only a user ID, with no further authentication measures in place. Because these user IDs are sequentially assigned, attackers could automate the process and potentially infiltrate every user account. Exposed data included first and last names, email addresses, birth dates, and user roles. In some cases, even geographical details and account status were reportedly accessible.
According to BobDaHacker, such sensitive information could be exploited for targeted phishing attacks. The risk is particularly pronounced given that many app users may be older or less technologically proficient, making them prime targets.
Additional Weaknesses Compounded the Issue
Beyond the API vulnerability, BobDaHacker also discovered additional flaws. The email verification process could be bypassed because the required confirmation code was retrievable via the API. This meant that attackers could register and validate accounts using email addresses they didn’t control.
Furthermore, issues with the authentication of emails sent by the app also came to light. Many email systems flagged messages as potentially fraudulent, complicating users’ ability to distinguish between legitimate and fake communications, thus increasing the likelihood of successful phishing attempts.
Delayed Response from Operators
BobDaHacker reported these vulnerabilities on January 3, 2026, contacting nine different staff members associated with Click to Pray and the Pope’s prayer network. Disturbingly, she received no response for over six months.
It wasn’t until the security portal Dark Reading brought the issue to public attention on July 24, 2026, that the app’s operators seemingly took action, closing the vulnerabilities. However, no official confirmation or acknowledgment has been provided to date, and BobDaHacker has yet to receive feedback on her initial report.
Whether the exposed data has been misused or whether affected users have been informed remains unclear. Given the size and intention of the platform, a swifter response and more transparent communication from the operators would have been appreciated.
Note: We rely on your support to continue our work. If you find value in what we do, consider marking us as a preferred source on Google and following us on Google News. Every bit of support helps!

