Apple rolls out iOS 26.4.2 to fix a flaw that allowed the FBI to access push notifications


Apple’s latest iOS update fixes a flaw in its notification database that made it possible for law enforcement to view deleted push notifications on a person’s iPhone or iPad. The security flaw was one way law enforcement agencies like the FBI could circumvent Apple’s strict stance towards user privacy, the Electronic Frontier Foundation writes, particularly since the company has required a court order to share notification data since 2023.

According to Apple’s update notes, iOS 26.4.2 introduces “improved data redaction” to address an issue where “notifications marked for deletion could be unexpectedly retained on the device.” The update is available now on “iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later and iPad mini 5th generation and later,” Apple says.

The FBI’s use of this particular iOS notification flaw was first reported on by 404 Media, who learned the agency used a tool to access Signal notification data stored locally on an iPhone even after it was deleted. Signal CEO Meredith Whitaker later acknowledged the issue on Bluesky, writing that “notifications for deleted [messages] shouldn’t remain in any OS notification database, and we’ve asked Apple to address this.” At the time, Whitaker directed Signal users to adjust their settings so that push notifications from the app didn’t include the name of the messenger or message content. In reaction to today’s news, Signal said on Bluesky that it is “very happy that today Apple issued a patch and a security advisory.”

The privacy of your notifications is vulnerable in at least two places, according to the EFF. In the cloud, where they get routed through a company’s servers and likely partially logged in metadata, and on the local storage of the phone where they’re received. Apple’s update should ideally make deleted notifications appropriately inaccessible, but limiting what’s actually visible in notifications in the first place is also worth considering.

Update, April 22, 6:40PM ET: This story was updated after publish to include comment from Signal.



Source link

  • Related Posts

    Honor’s new phones look like iPhones for Android

    Honor has announced the 600 and 600 Pro, which it calls “accessible flagships,” and they look… familiar. Especially in that orange. The Pro makes the iPhone comparison especially obvious thanks…

    You want your Moon landings in HD? So does NASA—here’s how it’s happening.

    Low-cost optical terminals NASA’s primary ground stations for optical communications on Artemis II were telescopes at the White Sands Complex in Las Cruces, New Mexico, and the Table Mountain Facility…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    NBA winners and losers: Thunder win, but Jalen Williams’ injury could loom large

    NBA winners and losers: Thunder win, but Jalen Williams’ injury could loom large

    No Merger, No Problem: Why American & Alaska Are Pivoting To Revenue Sharing

    No Merger, No Problem: Why American & Alaska Are Pivoting To Revenue Sharing

    Four female premiers on whether Christine Fréchette can avoid the ‘glass cliff’

    Four female premiers on whether Christine Fréchette can avoid the ‘glass cliff’

    Tesla Boosts Spending Plan to $25 Billion for AI, Robot Push

    Why are veggies so expensive? Consumers crunched by climbing cucumber costs

    Why are veggies so expensive? Consumers crunched by climbing cucumber costs

    An Independent Senate Hopeful Tries to Scare Off Montana Democrats

    An Independent Senate Hopeful Tries to Scare Off Montana Democrats