Apple released an iOS/iPadOS 26.4 developer beta that adds end-to-end encryption (E2EE) for RCS messaging in limited testing, with availability constrained by device/carrier support and currently limited to Apple-to-Apple RCS conversations. The implementation is tied to upgrading to RCS Universal Profile 3.0 built on the Messaging Layer Security (MLS) protocol, aligning with the GSMA’s prior move to standardize E2EE for RCS. The beta also expands platform hardening by allowing apps to opt into the full protections of Memory Integrity Enforcement (MIE) (beyond the previously available “Soft Mode”), and reporting indicates Apple may enable Stolen Device Protection by default in this release line.
Google released the first Android 17 beta with multiple privacy/security changes aimed at tightening network and cryptographic defaults and improving user control. Android 17 deprecates the android:usesCleartextTraffic manifest attribute; apps targeting Android 17+ that set usesCleartextTraffic="true" without a Network Security Configuration will have cleartext traffic blocked by default, pushing developers toward more granular policy via configuration files. The beta also introduces a public HPKE (Hybrid Public Key Encryption) Service Provider Interface, adds user preference controls for VoIP call history integration, and expands Wi‑Fi ranging for proximity detection and secure peer-to-peer discovery.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Apple released iOS 26.5 and iPadOS 26.5 with beta support for end-to-end encrypted RCS messaging between supported iPhones and Android devices using the latest Google Messages, enabled by default for new and existing chats. The update also patches more than 50 vulnerabilities across components including AppleJPEG, ImageIO, the kernel, mDNSResponder, and WebKit.
Apple said iOS 26.5 will add end-to-end encryption for RCS messaging between iPhones and Android devices, closing the prior cross-platform encryption gap. The feature is reportedly already present in the iOS 26.5 release candidate and requires iOS 26.5 on iPhone and the latest Google Messages version on Android.
Apple released the first public beta of iOS 26.5 with beta support for end-to-end encrypted RCS messaging after the feature was left out of the final iOS 26.4 release. Apple said the capability still works only on certain carriers and devices and indicates in chats when encryption is active.
Google said Android 17 is expected to reach the Platform Stability milestone in March, when APIs and app behavior definitions are planned to be finalized. The company also outlined quarterly updates, with Q2 as the only planned release introducing app-compatibility behavior changes and a minor SDK/API-focused release in Q4.
The same Apple developer beta added an opt-in option for apps to use full Memory Integrity Enforcement protections, aimed at improving memory safety against sophisticated spyware. Reporting on the beta also indicated iOS 26.4 may enable Stolen Device Protection by default, adding biometric checks and delays for sensitive account changes away from familiar locations.
In beta release notes, Apple said encrypted RCS support is available for testing now but will not ship in the 26.4 release. The company said broader customer rollout is planned in a future update across iOS, iPadOS, macOS, and watchOS.
Apple released an iOS and iPadOS 26.4 developer beta that introduces beta support for end-to-end encrypted RCS messaging. In the initial implementation, testing is limited to some devices and carriers and only works for Apple-to-Apple RCS conversations, not cross-platform chats.
The GSMA formally announced support for end-to-end encryption in RCS, with the capability tied to RCS Universal Profile 3.0 and the Messaging Layer Security protocol. This set the stage for vendors such as Apple to begin implementing encrypted RCS messaging.
Google released the first beta of Android 17 for supported Pixel devices and the Android Emulator, giving developers early access to platform changes. The beta includes privacy and security updates such as deprecating the usesCleartextTraffic manifest attribute, adding a public HPKE cryptography SPI, and new controls for VoIP call history integration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcezdnet.fr
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.