Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages

Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages

Apple has released emergency security updates for iOS and iPadOS to fix a vulnerability that allowed law enforcement to recover deleted notification data from iPhones, including message content from secure messaging applications like Signal. The flaw came to light after court testimony revealed that the FBI had extracted incoming Signal message fragments from a defendant’s iPhone in a criminal investigation tied to the 2025 attack on the Prairieland ICE Detention Facility in Texas, even though the Signal app had been deleted and messages were configured to disappear.

The vulnerability, tracked as CVE-2026-28950, was a logging issue in Apple’s Notification Services that caused notifications marked for deletion to be unexpectedly retained on the device. When notification previews are enabled, the operating system stores portions of incoming messages locally for lock screen display, creating forensic artefacts that remain accessible even after an app is deleted. Apple’s fix, released in iOS 26.4.2, iPadOS 26.4.2, iOS 18.7.8, and iPadOS 18.7.8, addresses the issue through improved data redaction. The updates cover devices from iPhone XR/XS through to iPhone 16 models and various iPad generations.

The FBI exploited this vulnerability during a criminal investigation, demonstrating how law enforcement can access supposedly secure communications through system-level storage rather than breaking encryption. The case highlights the tension between user privacy and law enforcement access, with the Electronic Frontier Foundation noting that this flaw allowed agencies to circumvent Apple’s strict privacy stance. Signal, whose users were directly affected, praised Apple for the quick action and confirmed that once users install the patch, all inadvertently preserved notifications will be deleted automatically.

This incident exposes a critical gap in mobile security – the assumption that encrypted messaging apps and disappearing messages guarantee complete privacy. In reality, notifications create forensic artefacts outside the encrypted application layer that can persist in system storage. The issue affects any messaging app that displays content in notifications, not just Signal, since the root cause lies within Apple’s notification framework rather than third-party software. For enterprises, this underscores the importance of reviewing notification settings and understanding that mobile device forensics can recover data users believe has been permanently deleted.

Click here for the original article.