The Vatican-backed Click To Pray app is at the centre of a cybersecurity controversy after ethical hacker BobDaHacker alleged that an API flaw exposed personal information from more than 700,000 user accounts. The researcher said the Pope-endorsed app leaked sensitive account details through an unsecured application programming interface (API). The vulnerability allegedly remained unresolved for months after it was reported.
The app, available in seven languages on iOS, Android, and the web, helps Catholics worldwide pray for the Holy Father's intentions. As of July 2026, it reportedly had 719,517 registered accounts.