Pope's official prayer app commits cardinal sin, leaks 700K+ users' info
Pope's official prayer app, ‘Divine Office,’ has suffered a significant data breach, exposing the personal information of over 700,000 users. The vulnerability stemmed from a flawed patch, allowing attackers to exploit a zero-day vulnerability within the app. This incident highlights ongoing security concerns surrounding mobile apps and the importance of rigorous testing and timely patching.
The ‘Divine Office’ prayer app, developed by the Knights of Malta, has been compromised, leading to a massive data breach. Approximately 700,000 users’ data has been exposed, including names, email addresses, and potentially other sensitive information. The vulnerability was identified through a failed Microsoft patch intended to address a previous issue, effectively creating a zero-day exploit. This incident underscores the risks associated with deploying incomplete or ineffective security updates in mobile applications. The Knights of Malta are a Catholic fraternal organization, and the app is used by Catholics worldwide for their daily prayers. The vulnerability was exploited by attackers, likely to use the data for phishing campaigns or other malicious activities. The Knights of Malta have yet to issue a public statement regarding the breach.