Hasty Briefsbeta

Bilingual

Click to Pray, Click to Leak: The Pope's Official App Exposes 700K+ User Emails

13 hours ago
  • A security researcher discovered an IDOR (Insecure Direct Object Reference) vulnerability in the Click To Pray app, allowing unauthorized access to over 700,000 user accounts' personal information including email addresses, names, and birth dates.
  • The vulnerability was reported on January 3, 2026, but received no response for six months, and the issue remained unaddressed until after media coverage from Dark Reading in July 2026.
  • The API endpoint lacked authorization checks, and the signup process returned a validation hash, enabling immediate account verification without email access.
  • The app's email authentication (SPF, DKIM, DMARC) was misconfigured, making legitimate emails indistinguishable from phishing attempts.
  • The vulnerability was eventually fixed after media exposure, with the endpoint now only returning public profile data (names) and implementing proper authorization checks.
  • The researcher received no acknowledgment or thanks from the organization, despite the fix being implemented silently.