news.mlab.sh
Back to the feed
vulnerability

Vatican's Official Prayer App Leaks 700K+ Global Users' PII

High
Summary

The Vatican's official prayer app, Click to Pray, is leaking the personal information of over 700,000 users due to an unsecured API endpoint. The vulnerability allows anyone to access names, email addresses, locations, and account status, including administrative details. The issue stems from a lack of proper authorization controls within the app's design and development. Despite the Vatican's own data protection regulations, the organization continues to expose user data, highlighting a broader issue of cybersecurity awareness and implementation within religious and communications organizations.

The Vatican’s official prayer app, Click to Pray, is exposing the personal information of over 700,000 users due to a critical vulnerability in its API endpoint. According to Dark Reading, the app, developed by La Machi Communication for Good Causes and owned by the Pope’s Worldwide Prayer Network, allows anyone with a browser to access user data, including names, email addresses, locations, and account status – even administrative privileges. The vulnerability is a direct result of a lack of proper authorization controls within the app's design and development.

“Click to Pray” is available on iOS and Android, and via a Web browser, offering users access to daily prayers and papal content. The vulnerability was discovered by white hat hacker “BobDaHacker,” who noted that IDORs (Insecure Direct Object References) are a common and persistent problem across industries. He emphasized that most frameworks handle authentication but not authorization, leaving developers to implement the second crucial check.

The Vatican has issued its own personal data protection regulation, Decree No. DCLVII, outlining the need for security measures, risk analyses, and reporting procedures. However, despite these regulations, the app continues to expose user data. Users can protect themselves by using techniques such as providing abbreviated names or alphanumeric handles and leveraging features like Apple’s “Hide my Email.”

La Machi Communication for Good Causes, a Spanish-language communications agency, designed and developed the app. The Pope’s Worldwide Prayer Network is the organization that owns the app. The vulnerability highlights a broader issue of cybersecurity awareness and implementation within organizations handling large volumes of personal data, regardless of their sector.

“BobDaHacker” argues that organizations handling hundreds of thousands of users’ personal data have a responsibility to protect it, regardless of whether they are a tech company or a church. He suggests that making security basics so accessible and so normalized that not having a security contact is as weird as not having a Contact page would be a significant step towards improving cybersecurity practices.

Read the full article at Dark Reading