Overview
- Researcher BobDaHacker says they reported the flaw on January 3 and received no replies for roughly six months before independent verification and press reports in late July led to a quiet patch.
- The bug was an Insecure Direct Object Reference (IDOR) that let anyone fetch other users by changing a sequential numeric ID in the API and the endpoint lacked rate limiting.
- Responses from the API included email address, first and last name, country, date of birth, role and deletion status, and the signup flow also returned the exact verification code used to confirm accounts.
- The exposed dataset and the app's email authentication problems make the largely older, Vatican‑affiliated user base especially vulnerable to targeted phishing and to attackers who could register and confirm accounts before real owners.
- The Vatican offered no public acknowledgement to the reporting researcher and the incident echoes prior Vatican app security lapses, raising questions about the network's disclosure, remediation processes and compliance with its own data‑protection rules.