Apple has released an out-of-band security update for iPhones and iPads to fix a privacy flaw that could allow deleted notification content, including message previews, to remain stored on devices longer than expected.
The issue, tracked as CVE-2026-28950, affects Notification Services and was addressed in iOS 26.4.2 and iPadOS 26.4.2, as well as iOS 18.7.8 and iPadOS 18.7.8 for older supported devices.
In its security advisory, Apple said the flaw could cause “notifications marked for deletion” to be “unexpectedly retained on the device,” adding that the issue was resolved through improved data redaction.
The vulnerability gained wider attention after reports that the FBI used the flaw to recover deleted Signal message previews from an iPhone during a criminal investigation in Texas.
According to media reports citing people familiar with court testimony, the case involved a Signal user who had deleted both messages and the Signal app from the device. Investigators were still able to recover previews of incoming messages stored in the phone’s push notification database, though they reportedly could not access messages sent from the device.
The case was linked to an investigation involving an attack on the Prairieland ICE detention center.
Signal, known for its end-to-end encryption and disappearing messages, welcomed Apple’s fix.
“We are very happy that today Apple issued a patch and a security advisory,” the company said in a statement posted on X.
Signal added that it had previously pushed for the change and praised Apple for acting quickly, saying private communication requires cooperation across the technology ecosystem.
Security experts note that the flaw is primarily a privacy and data-retention issue rather than a traditional remote hacking vulnerability. The main concern is that sensitive content visible in lock-screen notifications — such as message previews, legal discussions or confidential work communications — could remain accessible locally even after users believed it had been deleted.
Apple has not released exploit samples or a public proof-of-concept, and there are no known network indicators tied to the issue. Analysts say the most effective protection is ensuring devices are updated and limiting how much sensitive information appears in notifications.
Users handling confidential information are being urged to install the latest updates immediately and review notification settings to reduce message preview exposure.
add your comment
Terms of publication : Not to offend the writer, people, sacred things, or attack religions or the divine self, and refrain from racist incitement and insults.