The Pope’s Prayer App Has Been Leaking User Data For Months – With No Response

Researcher BobDaHacker found the six-month-old IDOR flaw exposing names, emails, and countries of 719,517 accounts

Al Landes Avatar
Al Landes Avatar

By

Image: Detroit Catholic | App Store – Edited by: Gadget Review

Key Takeaways

Key Takeaways

  • Researcher BobDaHacker found Click To Pray exposes 719,517 users’ data via basic IDOR flaw.
  • Pope’s Worldwide Prayer Network ignored multiple disclosure attempts over at least six months.
  • Exposed validated faith-community emails create a targeted phishing goldmine for bad actors.

Sign up for the Pope’s official prayer app, share your name and email, and join a global community of believers. Meanwhile, a security researcher reportedly changes a single number in a URL and pulls up your entire profile. That’s the alleged reality for up to 719,517 users of Click To Pray — the Vatican-backed app where the faithful share prayer intentions with the Holy Father. According to the researcher’s account, the flaw has been exploitable for at least six months, and the Pope’s Worldwide Prayer Network has not responded to multiple disclosure attempts.

A Flaw So Basic It Has a Name

An independent researcher reportedly found that Click To Pray’s backend hands over any user’s data to anyone who asks — no authorization required.

A researcher using the handle “BobDaHacker” claims to have discovered an insecure direct object reference, or IDOR. In plain terms: the app allegedly exposes numeric user IDs in URLs, and the server hands over any user’s profile data when asked — name, email address, and country of origin — with zero authorization checks applied.

The researcher says:

  • The first disclosure attempt went to nine official email addresses on January 3.
  • None replied.
  • The vulnerability was reportedly still live at the time of publication.

Straight Arrow independently confirmed the flaw, and Dark Reading first reported it publicly. The Pope’s Worldwide Prayer Network did not respond to either outlet’s request for comment.

“One of the most basic access control flaws in web security,” the researcher wrote. “You ask for your own data, the server gives it to you. You ask for someone else’s data, the server gives you that too.”

OWASP — the standard framework developers actually reference for web security — flags this exact class of bug as a top-tier vulnerability. Its presence here suggests either no security testing, or testing that nobody acted on.

This isn’t Click To Pray’s first confession. In 2019, UK firm Fidus Information Security found that the app’s $110 Bluetooth eRosary was returning login PINs in plain text via its API. It took Fidus ten minutes to find it, according to The Register. A Vatican spokesperson confirmed that flaw was fixed. History, apparently, didn’t stick.

A Phishing Goldmine, Courtesy of the Holy See

Nearly 720,000 validated faith-community email addresses sit reportedly exposed — a scammer’s dream list.

Names and emails aren’t passwords. But 720,000 validated addresses belonging to people who specifically trusted a Vatican-branded app are exactly the kind of list that makes phishing campaigns effective. The researcher reportedly described the dataset as a “phishing goldmine.” The user base skews older and deeply trusting of anything stamped with the Pope’s name — making “The Holy Father requests your urgent attention” a remarkably plausible subject line.

This isn’t an isolated pattern in faith-based apps. Pray.com exposed data on up to 10 million users through misconfigured cloud storage, according to PCMag. Religious platforms routinely collect sensitive behavioral data and protect it poorly — and Click To Pray fits that mold.

Click To Pray operates internationally, collecting personally identifiable information from EU users — putting it squarely under GDPR obligations, including breach notification requirements. Whether regulators have been informed remains unknown. The Pope’s Worldwide Prayer Network has not commented publicly.

If you use Click To Pray, treat your registered email address as potentially compromised. Watch for phishing attempts using religious or Vatican-themed lures. Until the app’s operators break their silence, assume your data has had an audience you didn’t pray for.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →