Vatican Click to Pray App API Flaw Exposes 700,000 User Records
Key Takeaways An unauthenticated API vulnerability in the Vatican’s “Click to Pray” app exposed the personal data of over 700,000 users. The flaw, an Insecure Direct Object...
Key Takeaways
- An unauthenticated API vulnerability in the Vatican’s “Click to Pray” app exposed the personal data of over 700,000 users.
- The flaw, an Insecure Direct Object Reference (IDOR), allowed unauthorized access to names, email addresses, country, and user roles.
- The vulnerability was discovered by ethical hacker BobDaHacker in January and remained unpatched at the time of reporting.
- Exposed data could facilitate highly convincing phishing and social engineering attacks targeting users of the papal prayer network.
- This incident underscores the critical importance of robust access control mechanisms and API authorization testing for organizations handling personal data.
The Vatican’s official “Click to Pray” application, designed to connect users with daily prayers and papal content, has inadvertently exposed the personal information of over 700,000 individuals. This significant data leak stems from a critical flaw in the app’s API, which permitted unauthorized access to user records without requiring any authentication.
Table Of Content
The vulnerability allowed anyone with a standard web browser to retrieve sensitive account data simply by manipulating user IDs, bypassing login procedures entirely. This security lapse affected users who had provided their names, email addresses, passwords, and in some cases, their country of origin when registering for the service.
Unauthenticated API Exposes User Records
The IDOR Flaw Explained
The exposure was identified by ethical hacker BobDaHacker, who uncovered an Insecure Direct Object Reference (IDOR) vulnerability in January. This type of flaw occurs when an application exposes a direct reference to an internal implementation object, such as a user ID, and fails to verify if the requesting user is authorized to access that specific object.
In the case of the “Click to Pray” app, the vulnerable API assigned sequential user IDs to each account. By merely incrementing these IDs in a web request, an unauthenticated individual could systematically access and view the associated account details for a vast number of users. DarkReading, which independently verified the issue, noted that the vulnerability was still accessible at the time of their publication, detailed in a technical report.
The exposed data included users’ full names, email addresses, country information, account deletion status, and assigned user roles (e.g., “PRAYER” for ordinary users, or staff-associated roles for lower-numbered accounts). This readily accessible data trove, which required no advanced technical expertise to extract, could be exploited by malicious actors.
Implications of the Exposure
As a DarkReading said in a report, this incident is not a malware attack but rather an access-control failure with potentially severe consequences. The ease with which this data could be harvested, simply through browser requests, significantly lowers the bar for criminals to craft sophisticated phishing campaigns and social engineering lures. The sequential nature of the user IDs made bulk data collection particularly straightforward.
Phishing Risks and Security Lessons
Threats Posed by Exposed Data
The availability of users’ names and email addresses allows attackers to create highly credible fraudulent emails. These could reference faith, prayer requests, donation appeals, or other Vatican-related content, making the messages appear legitimate. Victims are far more likely to open and interact with emails that are personalized with their actual account details, increasing the efficacy of such scams. Similar risks were observed in the NVIDIA personal data breach, where exposed identifiers also supported targeted phishing and credential attacks.
This incident serves as a stark reminder that robust access control is fundamental to web security. The <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/110b51be-5abb-4737-a65e-5acfd85eccc2/Vaticans-Click-to-Pray-App-Exposes-700000-Users-Through-Unauthenticated-API-Flaw.pdf?AWSAccessKeyId=ASIA2F3EMEYESJDZ4OVZ&Signature=bGShBgdK%2FfF9mvolzt4yGYK%2BElI%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEIX%2F%2F%2F%2
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.