idor2 articles
Pope's Prayer App Exposes 700,000 Users Because Nobody Bothered to Check Auth
The Pope's official prayer app, Click To Pray, has exposed the personal data of over 700,000 users — including names, email addresses, and dates of birth — due to a basic security flaw known as an Insecure Direct Object Reference (IDOR) bug, which allows anyone to access any user's data simply by changing a number in the API request. Ethical hacker BobDaHacker discovered and reported the vulnerability six months ago but has received no response from the Pope's Worldwide Prayer Network, and the flaw remains unpatched. The situation is made worse by additional security weaknesses in the signup process and poor email authentication, leaving users — many likely elderly and trusting of Vatican-affiliated communications — highly vulnerable to phishing attacks.
Researcher Pockets $78k After Finding Meta Support Data Wide Open
Security researcher Rony K Roy received a $78,000 bug bounty from Meta after discovering a critical vulnerability in Meta's backend support infrastructure, initially identified in January 2026. The flaw combined missing authorization, broken access control, and IDOR issues that, when chained together, could have allowed attackers to access sensitive customer support data, including emails, chat logs, and personal information shared with Meta support. Meta patched the vulnerability in April 2026 and found no evidence of malicious exploitation prior to the fix.