🟠 High  |  Source: The Register — Security


The official Vatican prayer app has exposed the personal data of over 700,000 users due to a security vulnerability. The breach highlights the risks of inadequate data protection practices in consumer-facing religious and lifestyle applications. With a large and potentially vulnerable user base, the incident raises concerns about regulatory compliance under GDPR and the broader handling of sensitive personal information.

Security Architect’s Take: Review any third-party or consumer applications integrated into your organisation’s ecosystem for exposed APIs and misconfigured storage — this incident is a reminder to enforce data minimisation and ensure regular third-party security assessments. If your organisation develops or procures apps handling personal data at scale, mandate penetration testing and cloud storage audits as part of the vendor onboarding process.

Original advisory: Pope’s official prayer app commits cardinal sin, leaks 700K+ users’ info