CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Vatican's Official Prayer App Leaks 700K+ Global Users' PII

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3167

As cited

Copy frozen at (site build).

breaches incidents

Vatican's Official Prayer App Leaks 700K+ Global Users' PII

Vatican's official prayer application contained a vulnerable API endpoint that exposed personal information for over 700,000 users worldwide. The exposed data included names, email addresses, location information, and site status that could be accessed without authentication through a standard web browser.

Why it matters: Anyone with internet access could have harvested sensitive personal information from a large global user base, affecting privacy and creating potential targets for phishing, identity theft, or other social engineering attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Vatican's Official Prayer App Leaks 700K+ Global Users' PII

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Vatican's Official Prayer App Leaks 700K+ Global Users' PII

Vatican's official prayer application exposed a misconfigured application programming interface (API) endpoint that leaked personally identifiable information on over 700,000 users globally, including names, email addresses, and locations. The data was accessible to anyone with a web browser and no authentication requirement.

Why it matters: Users of the Vatican's prayer app face identity theft and phishing risks from exposed personal details; practitioners should audit API security posture for unauthenticated endpoints leaking sensitive user data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary