THE Vatican's Click To Pray app, launched by Pope Francis in 2019, exposed personal data of over 700,000 users due to security flaws discovered by researcher BobDaHacker in January 2026. These included an API vulnerability that allowed unauthorized access to users' information such as email, names, and birth dates. A further issue enabled attackers to validate accounts using email addresses they didn’t control.
Despite multiple reports to the Vatican, the flaws remained unaddressed for over six months until media intervention prompted a fix. The incident highlights ongoing security issues with Vatican apps and user data protection concerns.