iOS 26.4.2—Update Now Warning Issued To All iPhone Users
iOS 26.4.2—Update Now Warning Issued To All iPhone Users
Publish Date: 2026-04-23 10:43:00
Source Domain: www.forbes.com
Apple’s iOS 26.4 and iOS 18.7.8 fix the same flaw, in Notification Services, where notifications marked for deletion could be unexpectedly retained on the device.
Apple iPhone
Update 10:45 a.m. EDT: This article, originally published at 03:47 a.m. EDT has been updated to include confirmation from Signal and expert commentary about the issue fixed in iOS 26.4.2 and iOS 18.7.8.
Apple has released iOS 26.4.2 and iOS 18.7.8, along with a warning to update your iPhone now. That’s because iOS 26.4 and iOS 18.7.8 fix a single security vulnerability in the iPhone software, which could be pretty serious.
Apple doesn’t provide much detail about what’s fixed in iOS 26.4.2 and iOS 18.7.8, to allow as many users to upgrade before attackers can get hold of the details. But it does reveal that iOS 26.4 and iOS 18.7.8 fix the same flaw, in Notification Services, where notifications marked for deletion could be unexpectedly retained on the device, according to Apple’s support page.
Tracked as CVE-2026-28950, it seems the issue was released as an emergency update for a reason. It appears to be the same vulnerability used by the FBI to extract copies of incoming Signal messages from a defendant’s iPhone due to copies of the content being saved in the push notification database, first reported by 404 Media.
While Apple doesn’t comment on the details of the fixes in iOS 18.7.8 and iOS 26.4.2, Bleeping Computer points out that “its description of notifications being retained on the device closely aligns with the type of data persistence described in that report.”
I have asked Apple to comment and will update this article if the iPhone maker responds.
Signal Confirms iOS 26.4.2 and iOS 18.7.8 Fix Known Issue
Signal has confirmed iOS 26.4.2 and iOS 18.7.8 fix the issue in question. “We are very happy that today Apple issued a patch and a security advisory,” Signal wrote on X, formerly Twitter, adding that the move comes following 404 Media’s reporting “that the FBI…