Pope's official prayer app commits cardinal sin, leaks 700K+ users' info

Summary

The Vatican's official prayer app, "Click To Pray," has a security flaw that exposed the personal information of over 700,000 users. The data exposed includes names, email addresses, and device information, and was accessible without authentication.

IFF Assessment

FOE

This vulnerability exposed sensitive user data, creating a significant risk for individuals and a win for potential attackers.

Defender Context

This incident highlights the ongoing risks associated with sensitive data exposure, even from seemingly benign applications. Defenders should be aware of the potential for misconfigurations and vulnerabilities in mobile apps, particularly those handling personal user information, and emphasize the importance of secure development practices and regular security audits for all digital services.

Read Full Story →