Apple rolls out iOS 26.4.2 to fix a flaw that allowed the FBI to access push notifications

Apple’s latest iOS update fixes a flaw in its notification database that made it possible for law enforcement to view deleted push notifications on a person’s iPhone or iPad. The security flaw was one way law enforcement agencies like the FBI could circumvent Apple’s strict stance towards user privacy, the Electronic Frontier Foundation writes, particularly since the company has required a court order to share notification data since 2023.

According to Apple’s update notes, iOS 26.4.2 introduces “improved data redaction” to address an issue where “notifications marked for deletion could be unexpectedly retained on the device.” The update is available now on “iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later and iPad mini 5th generation and later,” Apple says.

The FBI’s use of this particular iOS notification flaw was first reported on by 404 Media, who learned the agency used a tool to access Signal notification data stored locally on an iPhone even after it was deleted. Signal CEO Meredith Whitaker later acknowledged the issue on Bluesky, writing that “notifications for deleted [messages] shouldn’t remain in any OS notification database, and we’ve asked Apple to address this.” At the time, Whitaker directed Signal users to adjust their settings so that push notifications from the app didn’t include the name of the messenger or message content. In reaction to today’s news, Signal said on Bluesky that it is “very happy that today Apple issued a patch and a security advisory.”

The privacy of your notifications is vulnerable in at least two places, according to the EFF. In the cloud, where they get routed through a company’s servers and likely partially logged in metadata, and on the local storage of the phone where they’re received. Apple’s update should ideally make deleted notifications appropriately inaccessible, but limiting what’s actually visible in notifications in the first place is also worth considering.

Update, April 22, 6:40PM ET: This story was updated after publish to include comment from Signal.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/apple-rolls-out-ios-2642-to-fix-a-flaw-that-allowed-the-fbi-to-access-push-notifications-201153603.html?src=rss

Read more @ Engadget

Latest posts

Google rolling out big Snapseed 4.0 update for Android 

In June of 2025, Google surprisingly released a major update for Snapseed after a long dormancy. After confirming at the start of this year...

Walmart’s new 4K Google TV stick is the Chromecast replacement I needed [Gallery]

Walmart is in the process of launching its new Google TV streamer lineup and, while I’m pretty intrigued by the Pro model, it’s the...

Friday’s best Android app deals and freebies: Seoul Exorcist, WindWings, Farm Invasion, more

Your afternoon lineup of the best Android game and app deals is now ready to roll, including titles like Seoul Exorcist 1111, TripleFantasy Premium,...

Everybody wants to rule the AI world

Sometimes, companies pick CEOs based on carefully laid succession plans designed to maximize investor confidence and future performance. Other times, apparently, companies pick CEOs...

Tesla is recalling its cheaper Cybertruck because the wheels might fall off

Tesla is recalling its RWD Cybertruck Long Range over faulty brake rotors that could cause the wheels to fall off, as spotted earlier by...

What’s the role of a simple fitness band in the AI health era?

Fitness bands can’t be as simple as they once were before the AI health boom. | Photo by Amelia Holowaty Krales / The Verge This...

Boox’s new page-turning e-reader remote is a tiny two-button keyboard

Boox has announced its own alternative to the Kobo Remote that offers more functionality than just turning the page while reading on its tablets...

The future of game consoles is looking bleak

It's been a real good news / bad news week for Nintendo. Out of nowhere on Wednesday, the company announced a lush remake of...

Govee’s solar-powered string lights are already on sale for 20 percent off

I’m not sure if we’ve mentioned this yet, but Govee has been on a tear lately, having recently announced everything from rechargeable table lamps...

The company that owns Moog, Akai Pro, and Numark is buying Native Instruments

Native Instruments' suite of music production software and gear, including Traktor and Kontakt, will soon live under the inMusic umbrella alongside other music tech...