Apple released out-of-band updates for iOS 26.4.2, iPadOS 26.4.2, iOS 18.7.8, and iPadOS 18.7.8 to fix CVE-2026-28950, a privacy flaw in Notification Services that could cause notifications marked for deletion to remain stored on affected iPhones and iPads. Apple said the issue was caused by a logging problem and was resolved through improved data redaction, affecting supported devices across both current and older OS branches.
Apple did not say whether the bug had been exploited or why the fix was issued outside the normal release cycle, but government guidance from the Canadian Centre for Cyber Security urged users and administrators to apply the updates. Reporting on the patch noted similarities to a recent case in which investigators reportedly recovered Signal message content from an iPhone's internal notification storage after the app had been deleted, though Apple has not publicly connected the update to that incident.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-23, Signal confirmed that CVE-2026-28950 was the same Apple Notification Services flaw implicated in reporting that the FBI accessed retained Signal notification content from a suspect's iPhone after the app had been deleted. Signal also said the Apple patch removes inadvertently preserved notifications and advised users to limit notification preview content to reduce exposure.
Later on April 22, 2026, the Canadian Centre for Cyber Security issued advisory AV26-381 referencing Apple's iOS and iPadOS security updates. It advised users and administrators to review Apple's documentation and install the necessary updates for affected devices.
Apple published security notices for the affected iPhone and iPad releases, documenting CVE-2026-28950 and the impacted supported models. The advisories noted Apple's standard practice of withholding security issue details until investigations are complete and fixes are available.
On April 22, 2026, Apple released iOS 26.4.2, iPadOS 26.4.2, iOS 18.7.8, and iPadOS 18.7.8 to fix CVE-2026-28950, a Notification Services privacy flaw that could cause notifications marked for deletion to be unexpectedly retained on the device. Apple said the issue was caused by a logging problem and was addressed through improved data redaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
boingboing.net
Open sourcemalwarebytes.com
Open sourcezdnet.fr
Open sourcearstechnica.com
Open sourcesupport.apple.com
Open sourcebleepingcomputer.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.