On April 22, 2026, Apple released iOS 26.4.2 / iPadOS 26.4.2 alongside the legacy-track update iOS 18.7.8 / iPadOS 18.7.8. The releases address only one CVE, CVE-2026-28950, but it is the same notification flaw the U.S. Federal Bureau of Investigation (FBI) is reported to have exploited to extract deleted Signal messages from a defendant's iPhone in a criminal case. Apple shipped the fix on both the current and legacy iOS branches at the same time.
Release scope and supported devices
The current iOS 26 line received iOS 26.4.2 and iPadOS 26.4.2, while the legacy iOS 18 line received iOS 18.7.8 and iPadOS 18.7.8. Apple's security release page lists April 22, 2026 as the publication date, with the CVE entries themselves disclosed two days later on April 24.
The iOS 26.4.2 / iPadOS 26.4.2 update covers iPhone 11 and later, iPad Pro 12.9-inch (3rd generation) and later, iPad Pro 11-inch (1st generation) and later, iPad Air (3rd generation) and later, iPad (8th generation) and later, and iPad mini (5th generation) and later. Source: Apple, "About the security content of iOS 26.4.2 and iPadOS 26.4.2" (https://support.apple.com/ja-jp/127002)
iOS 18.7.8 / iPadOS 18.7.8 reaches further back, supporting iPhone XR, iPhone XS, iPhone XS Max, all iPhone 11 models, iPhone SE (2nd and 3rd generations), the iPhone 12 through 16 lineups, iPhone 16e, iPad mini (5th generation through A17 Pro), iPad (7th generation through A16), iPad Air (3rd to 5th generations), iPad Air 11 / 13-inch (M2 to M3), iPad Pro 11-inch (1st generation through M4), iPad Pro 12.9-inch (3rd to 6th generations), and iPad Pro 13-inch (M4). Devices that cannot move to iOS 26 still receive the same fix. Source: Apple, "About the security content of iOS 18.7.8 and iPadOS 18.7.8" (https://support.apple.com/ja-jp/127003)
Inside CVE-2026-28950: a logging issue in Notification Services
The patched flaw is CVE-2026-28950 in Notification Services. Apple describes the impact in one line: "Notifications marked for deletion could be unexpectedly retained on the device." The fix, in Apple's wording, "addressed a logging issue with improved data redaction." Source: Apple, "About the security content of iOS 26.4.2 and iPadOS 26.4.2" (https://support.apple.com/ja-jp/127002)
In practice, the contents of incoming push notifications were being kept inside an iOS notification database even after the user cleared the alerts or deleted the originating app. The vulnerability assumes physical possession of the device, but for messaging apps such as Signal that surface message text in the notification preview, that residual data effectively bypassed the app's end-to-end encryption when investigators imaged the phone. Source: Help Net Security, "Apple fixes iPhone bug that let FBI retrieve deleted Signal messages (CVE-2026-28950)" (https://www.helpnetsecurity.com/2026/04/23/cve-2026-28950-iphone-vulnerability-notifications-signal/)
The advisory does not mark the bug as exploited in the wild and credits no external researcher. Apple did not assign a CVSS score and has not provided technical detail beyond the brief advisory text.
How the FBI Signal case surfaced the bug, and Signal's confirmation
The flaw came to light through an April 2026 report in 404 Media that analyzed court records. According to the report, the FBI was able to recover incoming Signal messages from a defendant's iPhone by reading them out of the iOS notification database, even though the Signal app had been removed from the device. Signal's default notification preview includes the sender name and a portion of the message body, and that data persisted in the device's logs after the app's deletion, allowing investigators to reconstruct the conversations through the notification history. Source: The Hacker News, "Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages" (https://thehackernews.com/2026/04/apple-patches-ios-flaw-that-stored.html)
Signal subsequently confirmed publicly that CVE-2026-28950 and the bug used by the FBI are the same issue. The company said, "We're grateful to Apple for the quick action here, and for understanding and acting on the stakes of this kind of issue. It takes an ecosystem to preserve the fundamental human right to private communication." On user-side action, Signal added, "Note that no action is needed for this fix to protect Signal users on iOS. Once you install the patch, all inadvertently-preserved notifications will be deleted, and no forthcoming notifications will be preserved for deleted applications." Source: Help Net Security, "Apple fixes iPhone bug that let FBI retrieve deleted Signal messages (CVE-2026-28950)" (https://www.helpnetsecurity.com/2026/04/23/cve-2026-28950-iphone-vulnerability-notifications-signal/)
What users should do
The end-user response is straightforward. Devices on iOS 26 / iPadOS 26 should install 26.4.2 from Settings > General > Software Update; devices that cannot move beyond iOS 18 should apply 18.7.8 in the same way. Once installed, the patch routine cleans up any notification log entries that had been retained from before. Anyone using Signal, WhatsApp, or a mail client that displays message body text in notifications has a clear reason to apply the update promptly.
For users who want to limit how much notification content sits on the device in the first place, Signal offers a setting at Settings > Notifications > Notification content that lets you switch from the default "Name and Content" preview to "Name Only" or "No Name or Content," reducing what shows up on the lock screen and in iOS's notification logs. Combined with the iOS-side fix, this further lowers the risk if the device is ever physically seized.
Conclusion
iOS 26.4.2 / iPadOS 26.4.2 and iOS 18.7.8 / iPadOS 18.7.8 fix only one CVE, but the context behind CVE-2026-28950 — the FBI recovering Signal messages out of a notification database — exposes a long-running platform oversight. The update itself is small, and most devices will install it within minutes. Rather than a feature-driven release, this is a maintenance update that quietly closes the same hole on both the current and legacy iOS branches at once.