logo

Pope's official prayer app commits cardinal sin, leaks 700K+ users' info

ID: b844e1fc-c78a-56f2-bbe4-fc809f2b268b

STIX ID: report--b844e1fc-c78a-56f2-bbe4-fc809f2b268b

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

...
...

Click To Pray, the Pope-endorsed prayer app, has an IDOR vulnerability that allows enumeration and retrieval of 719,517 user records (emails, names, country, DOB, deletion status) by iterating sequential user IDs; the signup endpoint also returns verification UUIDs enabling account verification bypass, and email authentication failures make large-scale phishing trivial. The researcher disclosed the flaw months ago with no response from the operator.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.