flash on Nostr: ⚡️🙏 NEW - A major security flaw has been found in the Vatican’s official ...
⚡️🙏 NEW - A major security flaw has been found in the Vatican’s official Click to Pray app, potentially exposing the personal information of more than 700,000 users for at least six months.
According to security researcher BobDaHacker, the app’s API suffered from an Insecure Direct Object Reference (IDOR) vulnerability.
Anyone could change a user ID in a web request and access another person’s account details without logging in or permission.
The exposed information included:
- Names
- Email addresses
- Country of origin
- User role and account status
The researcher says there were around 719,500 registered accounts when the flaw was documented.
Published at
2026-07-26 07:51:48 UTCEvent JSON
{
"id": "9b7dd23690e1c13bc3fae4757537e0649bd117ae855d433cf89f2bd9944e05f7",
"pubkey": "4d7842051782e0d3feb034d150adc2b6bae4ee3b49786793bffa468b6f5b96b3",
"created_at": 1785052308,
"kind": 1,
"tags": [
[
"client",
"Primal iOS"
]
],
"content": "⚡️🙏 NEW - A major security flaw has been found in the Vatican’s official Click to Pray app, potentially exposing the personal information of more than 700,000 users for at least six months.\n\nAccording to security researcher BobDaHacker, the app’s API suffered from an Insecure Direct Object Reference (IDOR) vulnerability. \nAnyone could change a user ID in a web request and access another person’s account details without logging in or permission.\n\nThe exposed information included:\n- Names\n- Email addresses\n- Country of origin\n- User role and account status\n\nThe researcher says there were around 719,500 registered accounts when the flaw was documented. \n\nhttps://blossom.primal.net/95b34b5a27248dc19f6b3b6709869d085b184e9fa160eb78041d291c9562d28a.jpg\nhttps://blossom.primal.net/052144bbdd92e0bb78d807e14d4b76d478442b08e3f5c4420e2eaa44aa2606c9.jpg",
"sig": "f8ba7eea513e3dbf6133ee62332f7d06cc3cb6a0fb603a0da749578116fd87b754daca8afdab164a91d33c3550e49a15316249e3d81823ce9da3982471374a0f"
}