Apple released iOS 15.8.8 and iPadOS 15.8.8 on May 11, 2026[1]. The updates target six device categories — the iPhone 6s series, iPhone 7 series, iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) — all shipped between 2014 and 2019 and unable to move beyond the iOS 15 branch[1]. The release patches a single CVE, CVE-2026-28950, delivering to legacy hardware the same Notification Services fix that Apple first shipped on April 22 in iOS 26.4.2 and iOS 18.7.8, about three weeks later[1][4].

Release date, supported devices, and the sole fix

Apple's security release page 127114 lists the public availability of iOS 15.8.8 / iPadOS 15.8.8 as May 11, 2026[1]. The supported devices are iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)[1]. Each of these devices runs an A8, A8X, A9, or A10 Fusion chip and cannot meet the A11 Bionic requirement for iOS 16, leaving them stranded on the active iOS 15 branch[1][2].

The release fixes exactly one vulnerability, CVE-2026-28950, in the Notification Services component[1]. Apple's advisory states that "notifications marked for deletion could be unexpectedly retained on the device" and describes the fix as "a logging issue was addressed with improved data redaction"[1]. While the preceding 15.8.7 release on March 11 backported four Kernel and WebKit fixes, this 15.8.8 update is a single-CVE pinpoint patch, smaller in scope than the same-day iOS 18.7.9, iOS 16.7.16, or macOS Sequoia 15.7.7 branches[2][3].

CVE-2026-28950 — delayed backport of the notification bug tied to the FBI's Signal recovery case

CVE-2026-28950 was originally shipped on April 22, 2026, as an out-of-band patch in iOS 26.4.2 / iPadOS 26.4.2 and iOS 18.7.8 / iPadOS 18.7.8 to address the bug in current and near-current OS branches[4]. The issue came to light after reports that the FBI had been able to recover Signal messages that had already been deleted from a seized iPhone by reading them out of iOS notification data, prompting Apple's April 22 emergency release[4].

The technical pattern is that push notification payloads delivered by Signal and similar messengers were being retained in internal iOS logs even after the user dismissed the notifications or removed the app entirely[4]. While physical access to the device is required, the construction effectively allowed end-to-end-encrypted message contents to be read out of notification logs, bypassing the encryption layer[4]. iOS 15.8.8 and iPadOS 15.8.8 now extend that same fix to the six legacy device categories — the CVE number, affected component, and description text are identical to the April patch and to the May 11 iPadOS 17.7.11, iOS 16.7.16, and iOS 18.7.9 releases[1][4]. In addition to improving redaction, Apple's fix also purges previously retained notification log copies so that affected data is removed without any extra user action[4].

May 11's legacy roll-up and the longevity of the iOS 15 branch

iOS 15.8.8 and iPadOS 15.8.8 are part of the legacy roll-up Apple shipped together on May 11[2][3]. According to 9to5Mac's tally, the same day saw macOS Tahoe 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, iOS / iPadOS 18.7.9, iOS / iPadOS 16.7.16, and iPadOS 17.7.11 ship in parallel, covering everything from legacy to near-current branches[3]. The iOS 15 branch is the oldest of those, with supported hardware reaching back to the iPad Air 2 launched in October 2014 and the iPhone 6s and iPad mini 4 launched in September 2015[1][2].

From the iPhone 6s launch to today's patch, Apple has now shipped security updates for that hardware for 10 years and 8 months, and the company has not publicly stated how long it will continue maintaining the iOS 15 branch[1][2]. That iOS 15.8.8 limited itself to a single CVE suggests Apple's legacy security cadence has settled into a "selectively backport whichever serious bug appears in the current branch" operating phase[3][4]. The fact that the iOS 15 branch is being kept alive even for a fix that does not touch Kernel or WebKit exploit paths signals to users on these devices that staying on iOS 15 remains a viable option[1][3].

Summary

iOS 15.8.8 and iPadOS 15.8.8 are small maintenance releases that patch a single vulnerability, CVE-2026-28950, finally bringing the Notification Services log-retention fix that current OS branches received on April 22 to six legacy device categories. There are no new features, but because the underlying notification-retention issue was the one suspected of being exploited in the FBI Signal recovery case, users still running iOS 15 on devices such as iPhone 6s or iPad Air 2 should apply the update without delay.

Source:[1] https://support.apple.com/en-us/127114

Source:[2] https://support.apple.com/en-us/126632

Source:[3] https://9to5mac.com/2026/05/11/apple-just-released-new-updates-for-old-versions-of-ios-ipados-and-macos/

Source:[4] https://9to5mac.com/2026/04/22/ios-26-4-2-fixes-bug-that-allowed-deleted-notifications-to-be-retrieved/