CVE-2026-28950Patch(apple / ipados)

MEDIUMCVSS 6.2 · MEDIUM

Exploitation observed; activity peaked at 38 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly retained on the device.

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-359

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os

Threat summary

  • Active exploitation appears in 20 classified signals
  • Patch or workaround signal is available
  • 68 mentions across 13 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 20 signals
  • Patch or workaround mentioned in 59 signals
  • Technical details provided in 44 signals
  • General: 6 classified signals
  • Peaked 11d ago at 38 mentions (2026-04-23); latest day: 1
  • 68 total mentions across 13 days

Affected systems

Vendors
Products
ipadosiphone_os

Deep dive

Activity timeline68 mentions / 13d
010192938Mentions · 2026-04-22: 8Mentions · 2026-04-23: 38Mentions · 2026-04-24: 5Mentions · 2026-04-25: 6Mentions · 2026-04-26: 1Mentions · 2026-04-27: 2Mentions · 2026-04-29: 1Mentions · 2026-04-30: 1Mentions · 2026-05-01: 2Mentions · 2026-05-02: 1Mentions · 2026-05-03: 1Mentions · 2026-05-19: 1Mentions · 2026-07-10: 1Active Exploitation · 2026-04-22: 2Active Exploitation · 2026-04-23: 13Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-25: 1Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-05-19: 1Patch / Workaround · 2026-04-22: 7Patch / Workaround · 2026-04-23: 35Patch / Workaround · 2026-04-24: 4Patch / Workaround · 2026-04-25: 6Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-27: 2Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-04-22: 5Technical Details · 2026-04-23: 27Technical Details · 2026-04-24: 2Technical Details · 2026-04-25: 5Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-03: 1Technical Details · 2026-07-10: 104-2204-2304-2404-2504-2604-2704-2904-3005-0105-0205-0305-1907-10
Signal classification4 categories
Patch
5175.0%
Active Exploitation
913.2%
General
68.8%
Disclosure
22.9%
Referenced assets31 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-228
Active Exploitation1Patch7
2026-04-2338
Active Exploitation5Disclosure1General1Patch31
2026-04-245
General1Patch4
2026-04-256
Active Exploitation1Patch5
2026-04-261
Patch1
2026-04-272
Active Exploitation1Patch1
2026-04-291
Patch1
2026-04-301
General1
2026-05-012
General2
2026-05-021
General1
2026-05-031
Disclosure1
2026-05-191
Active Exploitation1
2026-07-101
Patch1
Full discourse20 posts
  • johnny@zeroxjf
    Patch

    The FBI extracted deleted Signal message previews from retained iPhone notification data, and Apple’s iOS 26.4.2 patch for CVE-2026-28950 shows why: instead of storing notification text, AppPrediction now stores only character counts, then purges old retained records on upgrade. https://t.co/nyJvGBbLzi

    Post summary

    Apple’s iOS 26.4.2 patch for CVE‑2026‑28950 resolves a notification data leakage flaw by limiting AppPrediction to character counts, preventing the FBI from retrieving deleted Signal message previews.

    3901053126.5K
    4.9K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    【悪かった】AppleがiOSにおいて削除後の通知が残存する不具合を修正。CVE-2026-28950。公式はデータ抹消の改善としているが、悪用の有無も含めた詳細には触れず。なお、FBIがSignalのメッセージを通知から回復したことが報じられていた。 https://www.bleepingcomputer.com/news/security/apple-fixes-ios-bug-that-retained-deleted-notification-data/

    Post summary

    Apple released a patch for CVE‑2026‑28950, addressing residual notification data retention; no evidence of exploitation or PoC is mentioned.

    1611912.5K
    7.6K followersView on X
  • Andac Guven@andacgvn
    Disclosure

    "Abi Apple çok güvenli ya" Apple fanboy tayfa anlık şokta. iOS bildirim sistemindeki bir açık (CVE-2026-28950) yüzünden, sildiğiniz mesajların ve uygulamaların bildirim logları cihazda gizlice saklanmaya devam ediyormuş! Sen git uçtan uca şifreli Signal kullan, mesajı sil, yetmesin uygulamayı kökten kaldır... Ama Apple sağ olsun, o bildirimleri arka planda FBI okusun diye günlük gibi tutsun. Uçtan uca şifreleme iyi güzel de, kilitli kapının anahtarı birilerinin elinde haberiniz yok. Hadi güncelleyin bakalım cihazları.

    Post summary

    The post discloses CVE-2026-28950, a flaw in iOS’s notification system that secretly stores deleted messages, and urges users to update their devices.

    2111641.6K
    4.0K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🚨 أبل تقفل الثغرة الي خلت FBI يقدرون يسترجعون رسائل Signal المحذوفة. رقم الثغرة: CVE-2026-28950. ⚙️المشكله كانت بسبب خدمة الإشعارات (Notification Services) بنظام iOS. المفروض لما تحذف رسالة من تطبيق Signal، الإشعار المرتبط فيها ينمسح من النظام بالكامل. بسبب الثغرة الإشعارات تبقى مخزنة في قاعدة بيانات الإشعارات المحلية في النظام ، حتى بعد ما تحذف الرسالة من التطبيق أو تحذف Signal بكبره من الجهاز!

    Post summary

    Apple has patched CVE‑2026‑28950, a notification service flaw that let deleted Signal messages be recovered (including by the FBI); the fix removes stored notifications from the local database after deletion.

    020532.2K
    49.3K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Active Exploitation

    🛡️ CVE-2026-28950 - Apple’s iOS 26.4.2 update patches a Notification Services flaw that could leave notifications marked for deletion unexpectedly retained on-device, which is a serious privacy issue because sensitive message previews can linger longer than users expect; public reporting says the flaw was actively exploited in the wild to recover deleted Signal message data, making this an urgent update for anyone handling private conversations. #iOS2642 #Apple #CVE202628950 #CyberSecurity #Privacy #ActivelyExploited https://support.apple.com/en-us/127002

    Post summary

    Apple’s iOS 26.4.2 update addresses a privacy flaw that lets deleted notifications remain on‑device, and the issue is actively exploited to recover deleted Signal messages, underscoring the need for immediate patching.

    1006085
    1.7K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Patch

    Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) https://www.helpnetsecurity.com/2026/04/23/cve-2026-28950-iphone-vulnerability-notifications-signal/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Apple has issued a fix for CVE‑2026‑28950, a vulnerability that exposed deleted Signal messages to FBI retrieval from iPhones.

    02230512
    194.5K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Patch

    اپل یک به‌روزرسانی نرم‌افزاری برای iOS و iPadOS منتشر کرد تا یک آسیب‌پذیری (CVE-2026-28950) در سرویس اعلان‌ها (Notification Services) را برطرف کند که طی آن اعلان‌های علامت‌گذاری‌شده برای حذف، به‌طور غیرمنتظره‌ای روی دستگاه نگه داشته می‌شدند. این نقص که به‌عنوان یک مشکل ثبت داده (logging issue) توصیف شده، در نسخه‌های iOS 26.4.2، iPadOS 26.4.2، iOS 18.7.8 و iPadOS 18.7.8 رفع شده و طیف گسترده‌ای از دستگاه‌های آیفون و آیپد را تحت تأثیر قرار می‌داد. این به‌روزرسانی در پی گزارشی از رسانه 404 Media منتشر شد که نشان می‌داد اداره تحقیقات فدرال آمریکا (FBI) توانسته با استفاده از ابزارهای جرم‌شناسی دیجیتال (forensic tools)، نسخه‌هایی از پیام‌های دریافتی در اپلیکیشن سیگنال (Signal) را از آیفون یک متهم استخراج کند، حتی پس از حذف این برنامه؛ چرا که محتوای پیام‌ها در پایگاه داده اعلان‌های دستگاه ذخیره مانده بود.

    Post summary

    Apple released an iOS/iPadOS patch for CVE‑2026‑28950, a logging issue in Notification Services, and FBI forensic tools were able to recover deleted Signal messages stored in the notification database.

    00050920
    19.0K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🛡️ CVE-2026-28950 — Apple patched a Notification Services bug where deleted notifications could still be retained on-device. #iOS2642 #Apple #CVE202628950 https://support.apple.com/en-us/127002

    Post summary

    Apple has released a patch for CVE‑2026‑28950, which addressed a Notification Services flaw that allowed deleted notifications to remain on user devices.

    1003085
    1.7K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 أبل تصحح ثغرة في نظام التشغيل iOS التي حفظت إشعارات Signal أصدرت شركة أبل تصحيحًا لي iOS و iPadOS لمعالجة خلل في خدمات الإشعارات التي حفظت إشعارات محذوفة على الجهاز. تم تعقب هذه الثغرة كـ CVE-2026-28950. حدث هذا الخلل نتيجة لضعف في آلية حذف الإشعارات. تأثرت أنظمة أبل بهذه الثغرة، وتم إصلاحها عبر التصحيح البرمجي. يُنصح بتحديث أنظمة التشغيل iOS و iPadOS لضمان الأمان. 🔗 للمزيد: https://thehackernews.com/2026/04/apple-patches-ios-flaw-that-stored.html

    Post summary

    Apple issued a patch for CVE‑2026‑28950, which involved a flaw where deleted Signal notifications were retained by iOS/iPadOS notification services. The advisory urges users to update their systems to mitigate the issue.

    00040442
    268 followersView on X
  • P1ayintraffic@p1ayintraffic
    Patch

    True for 26.4.2. Now 18.7.8 is more than a 'zero change' update for those of us on the 16 Pro Max holdout track. It finally polishes the 'DarkSword' patches from .7 and fixes the CVE-2026-28950 notification persistence bug. Super snappy compared to .7.7. Apple is definitely still optimizing the 18.x kernel for A18 Pro.

    Post summary

    Apple released the 18.7.8 update to address CVE-2026-28950, improving kernel stability and fixing notification persistence bugs.

    10021945
    34 followersView on X
  • Ryo@りんご大好き@macmacintosh
    Patch

    iOS/iPadOS 26.4.2 及び iOS/iPadOS 18.7.8 正式リリース。 バグ修正とセキュリティFix(CVE-2026-28950)

    Post summary

    Apple released iOS/iPadOS 26.4.2 and 18.7.8, addressing the CVE‑2026‑28950 security issue with a patch.

    00040431
    802 followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    🍎Apple patched CVE-2026-28950 deleted notifications were being retained in system cache. iOS 26.4.2 / iOS 18.7.8 now available. The FBI reportedly used this flaw to recover Signal messages from a device where the app had been uninstalled. Push notification previews = a compressed timeline of your working life. 2FA codes, work chats, calendar alerts all potentially recoverable via forensic tools. Signal confirmed: no action needed beyond installing the patch. → SecurityWeek / Signal @VulnerabilityNw | http://t.me/VulnerabilityNews/42140

    Post summary

    Apple patched CVE‑2026‑28950, yet the FBI reportedly exploited the flaw to retrieve deleted Signal messages, prompting users to update to the latest iOS release.

    11010489
    168 followersView on X
  • Help Net Security@helpnetsecurity
    Patch

    Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - https://www.helpnetsecurity.com/2026/04/23/cve-2026-28950-iphone-vulnerability-notifications-signal/ - @Apple @FBI @signalapp #iOS #iPad #Privacy #Vulnerability #Cybersecurity #CybersecurityNews

    Post summary

    Apple released a fix for CVE-2026-28950, a flaw that allowed FBI to recover deleted Signal messages, confirming the vulnerability was actively exploited before patching.

    20010346
    60.1K followersView on X
  • 七舅姥爷@yeahwu404
    Patch

    Apple 发布补丁修复 iOS 通知数据残留漏洞 Apple 发布安全更新修复了编号为 CVE-2026-28950 的通知服务漏洞。该漏洞导致已标记删除的通知仍可能意外留存在设备中,影响范围涵盖 iOS/iPadOS 26.4.2 及 18.7.8 等多个版本。Apple 通过改进数据脱敏技术解决了此问题,但尚未披露该漏洞是否已被用于攻击或其技术细节。 受影响的 Signal App 发文感谢 Apple 在此事上的迅速行动,以及他们对这类问题严重性的理解和重视。针对 iOS 上的 Signal 用户,无需额外操作来获得此修复的保护。一旦安装补丁,所有此前被意外保留的通知将被删除,未来也不会再为已删除的应用保留任何通知。

    Post summary

    Apple released a patch for CVE-2026-28950 that fixes notification service data residue on iOS/iPadOS, with no evidence of active exploitation or PoC.

    000212.7K
    18.8K followersView on X
  • CyberForget@cyberforget
    Patch

    @T3chFalcon The threat model is real. Deleting a message in an app doesn't wipe the OS-level notification log. Apple actually pushed iOS 26.4.2 (CVE-2026-28950) specifically to patch this database retention issue. Best move for maximum privacy: set sensitive apps to "No Name or Message.

    Post summary

    Apple released iOS 26.4.2 to fix a database retention issue that allowed persistent notification logs, enhancing privacy by ensuring deleted messages are fully purged.

    00020301
    6.1K followersView on X
  • CyberTLDR@CyberTLDR
    Patch

    Apple patched CVE-2026-28950, a flaw where iOS Notification Services unexpectedly retained deleted notifications. The bug allowed the FBI to recover Signal messages from a push notification database even after the app was uninstalled #FBI #Signal #iOS #Apple #cybersecurity

    Post summary

    Apple has fixed CVE‑2026‑28950, a flaw in iOS Notification Services that allowed deleted notifications to be retained, potentially enabling the FBI to recover Signal messages, but the vulnerability has been patched.

    10010106
    8 followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Apple patches CVE-2026-28950 after law enforcement recovered deleted Signal notifications from iOS devices using standard forensic tools. Bug caused notifications to persist in internal database even after app deletion. #DFIR_Radar https://t.co/l5KmHg6cfr

    Post summary

    Apple has released a patch for CVE-2026-28950, addressing a flaw that let Signal notifications persist in an internal database after app deletion, discovered via forensic analysis.

    10010172
    1.3K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Apple’s iOS 26.4.2 fixes a flaw (CVE-2026-28950) that let the FBI recover deleted Signal messages from notification logs. Update now to secure your private chats. #iOSUpdate #SignalApp #CyberSecurity #Privacy #Infosec #Apple #FBI #DataProtection https://securityonline.info/ios-patch-cve-2026-28950-signal-notification-fbi-forensics/ https://t.co/Awm3uej0Px

    Post summary

    Apple’s iOS 26.4.2 patch fixes CVE‑2026‑28950, which allowed the FBI to access deleted Signal messages via notification logs, and urges users to update immediately to maintain privacy.

    10010346
    11.3K followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    Vulnerability Alert — Apple iOS Apple patched CVE-2026-28950, a flaw that could retain deleted notifications on iOS and expose sensitive message content. The issue is fixed in the latest iOS and iPadOS updates. Update immediately. https://t.co/o1NOejWwWL

    Post summary

    Apple has released a patch for CVE‑2026‑28950, which allows retained deleted notifications to expose sensitive content. Users should update iOS and iPadOS immediately to mitigate the flaw.

    0002056
    260 followersView on X
  • Arif EMRE@arifemre062
    Patch

    CVE-2026-28950 was fixed on April 22, 2026 in iOS 26.4.2 and iOS 18.7.8. The fix uses improved data redaction and retroactively purges notification copies unexpectedly stored on-device.

    Post summary

    CVE‑2026‑28950 was addressed with a patch in iOS 26.4.2 and 18.7.8, which applied improved data redaction and retroactively cleared on‑device notification copies.

    10010188
    55 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---

Explore more