Pope’s Official Prayer App Exposed Over 700,000 Users’ Data

Hundreds of thousands of users' personal data were left exposed for months due to a critical security flaw in the Pope’s official prayer app. The issue, dubbed an IDOR (Insecure Direct Object Reference), allowed anyone to scrape the sensitive information of over 719,000 accounts.

Cybersecurity researcher BobDaHacker discovered the bug in January and reported it directly to the app's operators. However, despite its severity, the flaw remained active for six months until security outlet Dark Reading verified it and publicized the report. The Pope’s Worldwide Prayer Network did not publicly acknowledge BobDaHacker.

The security lapse affected accounts with names, emails, countries, and birthdates, all of which were easily accessible by anyone who exploited the bug. On top of that, the signup process handed back verification codes to confirm new accounts, adding another layer of vulnerability for potential phishing attacks.

Frequently Asked Questions

How many users’ data was exposed?

The official prayer app left over 719,000 user records vulnerable due to the security hole.

Who found the bug and when did it happen?

Cybersecurity researcher BobDaHacker reported the issue in January after discovering an IDOR vulnerability that allowed any attacker to access user data without proper authorization.

Why was the flaw left unpatched for so long?

The endpoint remained live until late July 2026, with no acknowledgment or response from officials at the Pope’s Worldwide Prayer Network.