{"id":1897548,"date":"2026-04-22T20:11:53","date_gmt":"2026-04-22T17:11:53","guid":{"rendered":"https:\/\/analyse.optim.biz\/?p=1897548"},"modified":"2026-04-22T20:11:53","modified_gmt":"2026-04-22T17:11:53","slug":"apple-rolls-out-ios-26-4-2-to-fix-a-flaw-that-allowed-the-fbi-to-access-push-notifications","status":"publish","type":"post","link":"https:\/\/analyse.optim.biz\/?p=1897548","title":{"rendered":"Apple rolls out iOS 26.4.2 to fix a flaw that allowed the FBI to access push notifications"},"content":{"rendered":"<p>[analyse_image type=&#8221;featured&#8221; src=&#8221;https:\/\/s.yimg.com\/ny\/api\/res\/1.2\/GYhw9Rik8xL0n_cohsJQSA&#8211;\/YXBwaWQ9aGlnaGxhbmRlcjt3PTEyMDA7aD02NzU-\/https:\/\/d29szjachogqwa.cloudfront.net\/images\/user-uploaded\/ios26_liquid_glass.jpeg&#8221;]<\/p>\n<article id=\"article-01a939cf-bec8-4287-a2e0-90fac1e2fb54\">\n<div>\n<div class=\"mx-auto md:px-10 md:max-w-[1220px]\">\n<nav class=\"prestige-breadcrumb relative mx-4 md:mx-0\" aria-label=\"breadcrumbs\">\n<ol class=\"no-scrollbar overflow-scroll whitespace-nowrap text-battleship\">\n<li class=\"inline\">\n<li class=\"inline-block cursor-default last:pr-10 md:last:pr-20 font-bold\">Cybersecurity<\/li>\n<\/ol>\n<\/nav>\n<header class=\"mb-4 px-4 md:mb-6 md:px-0\">\n<h1 class=\"layout-h1 my-2 font-bold leading-tight\">Apple rolls out iOS 26.4.2 to fix a flaw that allowed the FBI to access push notifications<\/h1>\n<h2 class=\"my-2 text-[18px] font-light leading-5 md:max-w-[660px] md:text-[20px]\/[28px]\">Data from deleted notifications was previously accessible on the local storage of some iOS devices.<\/h2>\n<div class=\"flex-col items-start lg:flex lg:flex-row lg:items-center lg:justify-between mt-6\">\n<div class=\"relative md:mr-[10px]\">\n<div class=\"flex items-center\">\n<div class=\"flex mr-2\">\n<div class=\"shrink-0 cursor-pointer inline-block size-[42px] lg:size-[48px]\"><img decoding=\"async\" alt role=\"img\" loading=\"lazy\" class=\"size-full rounded-full object-cover object-center shadow-[0_0_0_2px_#ffffff]\" src=\"https:\/\/s.yimg.com\/ny\/api\/res\/1.2\/z0DGTUGhtSngJHwR4_52VQ--\/YXBwaWQ9aGlnaGxhbmRlcjt3PTgwO2g9ODA-\/https:\/\/s.yimg.com\/os\/creatr-uploaded-images\/2024-12\/104d0e40-b283-11ef-80fd-c7df9234dfe5\"><\/div>\n<\/div>\n<div class=\"inline-block\">\n<div class=\"w-max text-sm\/5 font-semibold lg:!flex flex items-center\">\n<div class=\"flex flex-col\">\n<div class=\"flex w-max items-center\">Ian Carlos Campbell<\/div>\n<p><span class=\"font-normal sm:before:inline-block\">Contributing Reporter<\/span><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"lg:hidden\">\n<div class=\"text-xs text-dolphin dark:text-shark md:text-sm\/5 pt-4\">\n<div class=\"inline-block\"><span class=\"mr-1 hidden lg:inline\">Updated<\/span><time datetime=\"2026-04-22T20:11:53.000Z\">Wed, April 22, 2026 at 8:11 PM UTC<\/time><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"ml-0 mt-4 flex items-center lg:ml-3 lg:mt-0\">\n<div class=\"ml-0 mr-2\">\n<div class=\"relative flex\">Add Engadget on Google<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"hidden lg:block\">\n<div class=\"text-xs text-dolphin dark:text-shark md:text-sm\/5 pt-4\">\n<div class=\"inline-block\"><span class=\"mr-1 hidden lg:inline\">Updated<\/span><time datetime=\"2026-04-22T20:11:53.000Z\">Wed, April 22, 2026 at 8:11 PM UTC<\/time><\/div>\n<\/div>\n<\/div>\n<\/header>\n<\/div>\n<div class=\"grid grid-cols-1 gap-x-8 lg:gap-x-0 mx-auto md:px-10 md:max-w-[1220px] md:grid-cols-[[main-start]_1fr_[main-end_right-start]_min-content_[right-end]] lg:!gap-x-8\">\n<div class=\"md:col-main\" data-i13n-boundary=\"true\">\n<div>\n<div>\n<div class=\"grid grid-cols-[[fullbleed-start_body-start]_minmax(auto,750px)_[body-end_fullbleed-end]]\">\n<figure class=\"relative col-body mb-4\">\n<div class=\"relative overflow-hidden fig-image-round left-1\/2 w-screen -translate-x-1\/2 md:left-0 md:w-auto md:translate-x-0\"><img decoding=\"async\" alt class=\"object-cover object-center\" src=\"https:\/\/s.yimg.com\/ny\/api\/res\/1.2\/csX0pNGCFIBuThHboS8fKg--\/YXBwaWQ9aGlnaGxhbmRlcjt3PTEyNDI7aD02OTk-\/https:\/\/s.yimg.com\/uu\/api\/res\/1.2\/sbKPXLIDjwAFXBH_3kY8og--~B\/aD0xMzUwO3c9MjQwMDthcHBpZD15dGFjaHlvbg--\/https:\/\/d29szjachogqwa.cloudfront.net\/images\/user-uploaded\/ios26_liquid_glass.jpeg\"><\/div><figcaption class=\"relative text-[0.875rem]\/[1.25rem] figure-caption mt-1 line-clamp-2 mt-2.5 md:mt-2 pr-2.5\">\n<div><span>Mat Smith for Engadget<\/span><\/div>\n<\/figcaption><\/figure>\n<\/div>\n<\/div>\n<div class=\"grid grid-cols-article-mobile md:grid-cols-article lg:max-w-[750px] drop-cap\" data-article-body=\"true\">\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\">Apple&#8217;s latest iOS update fixes a flaw in its notification database that made it possible for law enforcement to view deleted push notifications on a person&#8217;s iPhone or iPad. The security flaw was one way law enforcement agencies like the FBI could circumvent Apple&#8217;s strict stance towards user privacy, the Electronic Frontier Foundation writes, particularly since the company has required a court order to share notification data since 2023.<\/p>\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\">According to Apple&#8217;s update notes, iOS 26.4.2 introduces &#8220;improved data redaction&#8221; to address an issue where &#8220;notifications marked for deletion could be unexpectedly retained on the device.&#8221; The update is available now on &#8220;iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later and iPad mini 5th generation and later,&#8221; Apple says.<\/p>\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\">The FBI&#8217;s use of this particular iOS notification flaw was first reported on by <em>404 Media<\/em>, who learned the agency used a tool to access Signal notification data stored locally on an iPhone even after it was deleted. Signal CEO Meredith Whitaker later acknowledged the issue on Bluesky, writing that &#8220;notifications for deleted [messages] shouldn&#8217;t remain in any OS notification database, and we&#8217;ve asked Apple to address this.&#8221; At the time, Whitaker directed Signal users to adjust their settings so that push notifications from the app didn\u2019t include the name of the messenger or message content. In reaction to today\u2019s news, Signal said on Bluesky that it is \u201cvery happy that today Apple issued a patch and a security advisory.\u201d<\/p>\n<div class=\"col-fullbleed mb-4 bg-marshmallow pb-5 dark:bg-ramones md:invisible md:mb-0 md:h-0 md:overflow-hidden md:pb-0\">\n<div class=\"py-2 text-center text-xs uppercase\">Advertisement<\/div>\n<div class=\"flex w-full flex-nowrap justify-center\">\n<div class=\"flex\" id=\"_R_ch9nam95feiv5tilbH1_\">\n<div class=\"flex size-full items-center justify-center bg-marshmallow text-center leading-3\">Advertisement<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"col-body mb-4 hidden pb-5 dark:bg-ramones md:block\">\n<div class=\"flex w-full flex-nowrap justify-center\">\n<div class=\"flex\" id=\"_R_kh9nam95feiv5tilbH1_\">\n<div class=\"flex size-full items-center justify-center bg-marshmallow text-center leading-3\">Advertisement<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\">The privacy of your notifications is vulnerable in at least two places, according to the EFF. In the cloud, where they get routed through a company&#8217;s servers and likely partially logged in metadata, and on the local storage of the phone where they&#8217;re received. Apple&#8217;s update should ideally make deleted notifications appropriately inaccessible, but limiting what&#8217;s actually visible in notifications in the first place is also worth considering.<\/p>\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\"><strong>Update, April 22, 6:40PM ET: <\/strong>This story was updated after publish to include comment from Signal.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"md:col-main grid grid-cols-article-mobile md:grid-cols-article lg:max-w-[750px]\">\n<div class=\"no-scrollbar col-body mx-4 mb-8 mt-2.5 overflow-x-scroll whitespace-nowrap md:mx-0 md:max-w-[750px] md:overflow-x-visible md:hidden\">\n<div class=\"mx-auto max-w-screen-sm\">\n<ul class=\"inline-flex text-xs md:text-sm\">\n<li class=\"mr-6\">About our ads<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/article>\n<div class=\"grid grid-cols-article-mobile md:grid-cols-article lg:max-w-[750px] drop-cap\" data-article-body=\"true\">\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\">Apple&#8217;s latest iOS update fixes a flaw in its notification database that made it possible for law enforcement to view deleted push notifications on a person&#8217;s iPhone or iPad. The security flaw was one way law enforcement agencies like the FBI could circumvent Apple&#8217;s strict stance towards user privacy, the Electronic Frontier Foundation writes, particularly since the company has required a court order to share notification data since 2023.<\/p>\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\">According to Apple&#8217;s update notes, iOS 26.4.2 introduces &#8220;improved data redaction&#8221; to address an issue where &#8220;notifications marked for deletion could be unexpectedly retained on the device.&#8221; The update is available now on &#8220;iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later and iPad mini 5th generation and later,&#8221; Apple says.<\/p>\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\">The FBI&#8217;s use of this particular iOS notification flaw was first reported on by <em>404 Media<\/em>, who learned the agency used a tool to access Signal notification data stored locally on an iPhone even after it was deleted. Signal CEO Meredith Whitaker later acknowledged the issue on Bluesky, writing that &#8220;notifications for deleted [messages] shouldn&#8217;t remain in any OS notification database, and we&#8217;ve asked Apple to address this.&#8221; At the time, Whitaker directed Signal users to adjust their settings so that push notifications from the app didn\u2019t include the name of the messenger or message content. In reaction to today\u2019s news, Signal said on Bluesky that it is \u201cvery happy that today Apple issued a patch and a security advisory.\u201d<\/p>\n<div class=\"col-fullbleed mb-4 bg-marshmallow pb-5 dark:bg-ramones md:invisible md:mb-0 md:h-0 md:overflow-hidden md:pb-0\">\n<div class=\"py-2 text-center text-xs uppercase\">Advertisement<\/div>\n<div class=\"flex w-full flex-nowrap justify-center\">\n<div class=\"flex\" id=\"_R_ch9nam95feiv5tilbH1_\">\n<div class=\"flex size-full items-center justify-center bg-marshmallow text-center leading-3\">Advertisement<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"col-body mb-4 hidden pb-5 dark:bg-ramones md:block\">\n<div class=\"flex w-full flex-nowrap justify-center\">\n<div class=\"flex\" id=\"_R_kh9nam95feiv5tilbH1_\">\n<div class=\"flex size-full items-center justify-center bg-marshmallow text-center leading-3\">Advertisement<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\">The privacy of your notifications is vulnerable in at least two places, according to the EFF. In the cloud, where they get routed through a company&#8217;s servers and likely partially logged in metadata, and on the local storage of the phone where they&#8217;re received. Apple&#8217;s update should ideally make deleted notifications appropriately inaccessible, but limiting what&#8217;s actually visible in notifications in the first place is also worth considering.<\/p>\n<p class=\"col-body mb-4 leading-7 text-[18px] md:leading-8 break-words min-w-0 charcoal-color\"><strong>Update, April 22, 6:40PM ET: <\/strong>This story was updated after publish to include comment from Signal.<\/p>\n<\/div>\n<p>[analyse_source url=&#8221;https:\/\/www.engadget.com\/cybersecurity\/apple-rolls-out-ios-2642-to-fix-a-flaw-that-allowed-the-fbi-to-access-push-notifications-201153603.html&#8221;]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[analyse_image type=&#8221;featured&#8221; src=&#8221;https:\/\/s.yimg.com\/ny\/api\/res\/1.2\/GYhw9Rik8xL0n_cohsJQSA&#8211;\/YXBwaWQ9aGlnaGxhbmRlcjt3PTEyMDA7aD02NzU-\/https:\/\/d29szjachogqwa.cloudfront.net\/images\/user-uploaded\/ios26_liquid_glass.jpeg&#8221;] Cybersecurity Apple rolls out iOS 26.4.2 to fix a flaw that allowed the FBI to access push notifications Data from deleted notifications was previously accessible on the local storage of some iOS devices. Ian Carlos Campbell Contributing Reporter UpdatedWed, April 22, 2026 at 8:11 PM UTC Add Engadget on Google UpdatedWed, April [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[226,63],"class_list":["post-1897548","post","type-post","status-publish","format-standard","hentry","category-politics","tag-crawlmanager","tag-engadget-com"],"_links":{"self":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts\/1897548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1897548"}],"version-history":[{"count":0,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts\/1897548\/revisions"}],"wp:attachment":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1897548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1897548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1897548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}