iOS Vulnerability - Apple Fixes Deleted Notifications Issue

Apple has fixed a major flaw in iOS that allowed deleted notifications to linger, risking user privacy. This affects many devices, including iPhones and iPads. Users should update their devices to ensure sensitive data is no longer retrievable.

VulnerabilitiesHIGHUpdated: Published:
Featured image for iOS Vulnerability - Apple Fixes Deleted Notifications Issue

Original Reporting

SASecurity Affairs·Pierluigi Paganini

AI Summary

CyberPings AI·Reviewed by Rohit Rana

🎯Basically, a flaw in iOS let deleted messages stay on your phone, but Apple fixed it.

What Happened

Apple has released an important update for iOS and iPadOS to address a serious vulnerability identified as CVE-2026-28950. This flaw was found in the Notification Services, which improperly stored notifications even after users deleted them. This oversight meant that sensitive data, including messages from encrypted apps like Signal, could potentially be recovered.

The Flaw

The issue stemmed from how iOS managed notification data. When a message was sent to a user via Signal, it would be pushed to the device and temporarily stored by Apple's notification system. Even if the user deleted the message from Signal, remnants of that notification could remain in the device's database, making it accessible through forensic methods.

Who's Affected

The flaw impacts a wide range of devices, including:

🏭

iPhone 11 and

iPhone 11 and later models

🏥

iPad Pro (various generations)

🏦

iPad Air (3rd

iPad Air (3rd generation and later)

🏛️

iPad mini (5th

iPad mini (5th generation and later)

🏫

iPhone SE (2nd

iPhone SE (2nd and 3rd generations)

🛒

iPhone 12, 13,

iPhone 12, 13, 14, and 15 series

What Data Was Exposed

The vulnerability primarily affected incoming messages. While outgoing messages do not leave a trace in the notification system, incoming messages could be retrieved even after the app was deleted. This could lead to sensitive information being exposed, especially in legal contexts, as highlighted by recent FBI investigations.

What You Should Do

Apple has released updates (iOS 26.4.2 and iPadOS 26.4.2) that address this vulnerability. Users are strongly encouraged to install these updates immediately. After installing the patch, any previously stored notifications will be deleted, and future notifications from deleted applications will not be retained. Signal has confirmed that no user action is required beyond updating their devices.

Conclusion

This incident highlights a crucial aspect of mobile privacy: the assumption that deleting messages from apps like Signal guarantees their complete removal. Users must remain vigilant and ensure their devices are updated to protect against such vulnerabilities. Apple’s quick response to this flaw is a positive step towards enhancing user privacy and security.

🔒 Pro Insight

🔒 Pro insight: This vulnerability underscores the importance of understanding how mobile operating systems handle notification data, even from encrypted apps.

Related Pings