Apple rolls out iOS 26.4.2 to fix a flaw that allowed the FBI to access push notifications


Apple’s latest iOS update fixes a flaw in its notification database that made it possible for law enforcement to view deleted push notifications on a person’s iPhone or iPad. The security flaw was one way law enforcement agencies like the FBI could circumvent Apple’s strict stance towards user privacy, the Electronic Frontier Foundation writes, particularly since the company has required a court order to share notification data since 2023.

According to Apple’s update notes, iOS 26.4.2 introduces “improved data redaction” to address an issue where “notifications marked for deletion could be unexpectedly retained on the device.” The update is available now on “iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later and iPad mini 5th generation and later,” Apple says.

The FBI’s use of this particular iOS notification flaw was first reported on by 404 Media, who learned the agency used a tool to access Signal notification data stored locally on an iPhone even after it was deleted. Signal CEO Meredith Whitaker later acknowledged the issue on Bluesky, writing that “notifications for deleted [messages] shouldn’t remain in any OS notification database, and we’ve asked Apple to address this.” At the time, Whitaker directed Signal users to adjust their settings so that push notifications from the app didn’t include the name of the messenger or message content. In reaction to today’s news, Signal said on Bluesky that it is “very happy that today Apple issued a patch and a security advisory.”

The privacy of your notifications is vulnerable in at least two places, according to the EFF. In the cloud, where they get routed through a company’s servers and likely partially logged in metadata, and on the local storage of the phone where they’re received. Apple’s update should ideally make deleted notifications appropriately inaccessible, but limiting what’s actually visible in notifications in the first place is also worth considering.

Update, April 22, 6:40PM ET: This story was updated after publish to include comment from Signal.



Source link

  • Related Posts

    Best Fitbit Models for Beginners, Athletes, and Kids (2026)

    It’s been five years since Google officially acquired Fitbit for a reported $2.1 billion, grabbing hardware and software teams that also absorbed assets from Pebble, which Fitbit itself acquired in…

    Hands on with X’s new AI-powered custom feeds

    Bluesky isn’t the only company leaning into AI to help build custom feeds, it seems. Amid a slate of recent product releases, X this week announced the launch of Grok-powered…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Stanley Cup playoffs: Judging early first-round overreactions

    Stanley Cup playoffs: Judging early first-round overreactions

    Navy secretary fired and our NFL draft predictions: Morning Rundown

    Navy secretary fired and our NFL draft predictions: Morning Rundown

    UK business activity rose more than expected in April

    The Curator: Must-have linen clothing for every wardrobe – National

    The Curator: Must-have linen clothing for every wardrobe – National

    6 Aircraft With The Highest Passenger Capacity

    6 Aircraft With The Highest Passenger Capacity

    20 Luxurious Mother’s Day Gift Ideas

    20 Luxurious Mother’s Day Gift Ideas