Apple on Wednesday released iOS 26.4.2 and iPadOS 26.4.2, patching a vulnerability in the iPhone notification system that the FBI recently exploited to recover deleted Signal messages from a suspect's device. For older devices running iOS 18, the company also released iOS 18.7.8 and iPadOS 18.7.8.
The flaw resided in how iOS handled notification data. According to Apple, due to a logging system error, notification content that was intended to be deleted continued to be stored in the device's internal notification database. The company stated it addressed the issue through "improved data redaction."
The vulnerability came to light during a terrorism trial in Texas. Witness testimony revealed how FBI agents were able to extract incoming Signal messages from the defendant’s iPhone—even though the encrypted messenger had been uninstalled and the disappearing messages feature was enabled. Forensic experts utilized tools like Cellebrite to pull data from the push notification cache, where iOS stores message content when lock screen previews are enabled.
The case, dubbed "Prairieland," involved defendants accused of a shooting at an ICE detention facility. Testimony confirmed that message previews for defendant Lynette Sharp remained in the notification database even after the app was deleted—a fact first reported by 404 Media. Privacy researchers noted that this vulnerability affected not only Signal, but any messenger with notification previews enabled, including WhatsApp, Telegram, and iMessage.
iOS 26.4.2 (build 23E261) arrives two weeks after iOS 26.4.1, which was released on April 8 to fix iCloud sync issues but lacked security patches. Today's update is the first in the 26.4 cycle to include security fixes, although as of Wednesday, Apple had not yet published specific CVE identifiers.
Simultaneously, Apple is testing iOS 26.5—currently in its third beta—with a public release expected in May. This update will lay the groundwork for end-to-end encryption for RCS messages between iPhone and Android devices, as well as for advertisements in Apple Maps.
Signal does not transmit message content to Apple's servers; messages are decrypted locally before notifications are generated. However, if lock screen previews are enabled, iOS caches the decrypted text in system storage, creating a forensic artifact that persists even after messages and the app itself are deleted. According to digital forensics experts, only a factory reset can completely clear the notification database.
Users wishing to protect their data immediately without waiting for an update can disable notification previews in Settings by selecting "Never" for the "Show Previews" option, or hide message content specifically for individual apps.
month
week
day