Apple issues emergency iOS update to fix privacy flaw exposing deleted messages

Apple issues emergency iOS update to fix privacy flaw exposing deleted messages
Saturday 25 April 2026 - 10:50

Apple has released an out-of-band security update for iPhones and iPads to fix a privacy flaw that could allow deleted notification content, including message previews, to remain stored on devices longer than expected.

The issue, tracked as CVE-2026-28950, affects Notification Services and was addressed in iOS 26.4.2 and iPadOS 26.4.2, as well as iOS 18.7.8 and iPadOS 18.7.8 for older supported devices.

In its security advisory, Apple said the flaw could cause “notifications marked for deletion” to be “unexpectedly retained on the device,” adding that the issue was resolved through improved data redaction.

The vulnerability gained wider attention after reports that the FBI used the flaw to recover deleted Signal message previews from an iPhone during a criminal investigation in Texas.

According to media reports citing people familiar with court testimony, the case involved a Signal user who had deleted both messages and the Signal app from the device. Investigators were still able to recover previews of incoming messages stored in the phone’s push notification database, though they reportedly could not access messages sent from the device.

The case was linked to an investigation involving an attack on the Prairieland ICE detention center.

Signal, known for its end-to-end encryption and disappearing messages, welcomed Apple’s fix.

“We are very happy that today Apple issued a patch and a security advisory,” the company said in a statement posted on X.

Signal added that it had previously pushed for the change and praised Apple for acting quickly, saying private communication requires cooperation across the technology ecosystem.

Security experts note that the flaw is primarily a privacy and data-retention issue rather than a traditional remote hacking vulnerability. The main concern is that sensitive content visible in lock-screen notifications — such as message previews, legal discussions or confidential work communications — could remain accessible locally even after users believed it had been deleted.

Apple has not released exploit samples or a public proof-of-concept, and there are no known network indicators tied to the issue. Analysts say the most effective protection is ensuring devices are updated and limiting how much sensitive information appears in notifications.

Users handling confidential information are being urged to install the latest updates immediately and review notification settings to reduce message preview exposure.

add your comment

Terms of publication : Not to offend the writer, people, sacred things, or attack religions or the divine self, and refrain from racist incitement and insults.

Politics
🔴  Morocco election 2026 live tracker: Constitutional Union says gov't formation talks to continue, RNI 'ready' to join next government under PAM
Thursday 1 October 2026 - 12:03

🔴 Morocco election 2026 live tracker: Constitutional Union says gov't formation talks to continue, RNI 'ready' to join next government under PAM

News
Spanish king’s first visits to Ceuta, Melilla set for Oct. 13-14
Thursday 1 October 2026 - 10:30

Spanish king’s first visits to Ceuta, Melilla set for Oct. 13-14

Economy
Morocco’s financial intelligence unit probes luxury car purchases over suspected money laundering
Thursday 1 October 2026 - 10:12

Morocco’s financial intelligence unit probes luxury car purchases over suspected money laundering

News
Morocco leads France’s international student intake, OECD report finds
Thursday 1 October 2026 - 09:38

Morocco leads France’s international student intake, OECD report finds