惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
U
Unit 42
Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
雷峰网
雷峰网
Microsoft Security Blog
Microsoft Security Blog
爱范儿
爱范儿
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园_首页
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
L
LangChain Blog
Engineering at Meta
Engineering at Meta
量子位
有赞技术团队
有赞技术团队
博客园 - 【当耐特】
A
About on SuperTechFans
Y
Y Combinator Blog

Latest news

Why I'm recommending last year's phones over 2026 models - with one exception This powerful Gemini setting made my AI results way more personal and accurate After testing this HP laptop, I get why its 'boring' design is adored by business users The best TV antenna of 2026: Expert tested Your old iPad or Android tablet can be your new smart home panel - here's how Apple's original AirTag still tracks effectively, and you can get a 4-pack for its best price ever How to qualify for Apple's education discount - and get a $499 MacBook Neo for school T-Mobile will give you a Samsung Galaxy Watch 8 for free - how to get yours Prolonged AI use can be hazardous to your health and work: 4 ways to stay safe Verizon will give you a free iPad or Apple Watch with your next iPhone - how the deal works The best laptops of 2026: Expert tested and reviewed I hid 4 Bluetooth trackers (including AirTags) to test their reliability - here's how Android rivals compared I stopped using my iPhone's hotspot after testing this 5G router - and that won't change The best Kindles in 2026: Expert recommended Does Best Buy price match? Everything to know about matching prices online and in-store The best WordPress hosting services of 2026: Expert tested and reviewed The best Apple Watch of 2026: Expert tested and reviewed The best TV screen cleaners of 2026: Expert recommended The best 50-inch TVs of 2026: Expert tested I traded my Sonos Era 300 for Denon's new home speaker - and see no reason to go back AI-powered website builders have come a long way - here's your best option in 2026 Amazon just slashed $250 off the Google Pixel 10 - and a Prime subscription isn't required I found the apps slowing down my PC - how to kill the biggest memory hogs These companies are actually upskilling their workers for AI - here's how they do it Verizon will give you Meta Ray-Bans for free with this Fios Internet deal - how to get yours I tried the new Gemini app for Mac - it has one major advantage over the web version How Google's updated AI Mode will ease your tab clutter when you search Why this MagSafe battery pack is our readers' favorite model right now - especially at its price T-Mobile will give you a Google Pixel 10a for free - plus an extra gift OpenAI's Codex Desktop can run your computer now - and has its own browser
Apple just fixed an iOS flaw exploited by the FBI - here'...
Written by Lance Whitney, ContributorContributor April 23, 2026 · 2026-04-24 · via Latest news
Apple's iOS 26.4.2 update for the iPhone
Lance Whitney/ZDNET

Follow ZDNET: Add us as a preferred source on Google.


ZDNET's key takeaways

  • iOS 26.4.2 fixes a flaw that allowed access to deleted texts.
  • The FBI exploited this flaw to recover messages from a Signal user.
  • The patch should protect other messaging apps from this weakness.

Many people use the popular Signal app to send and receive encrypted text messages. As an added bonus, you can set all texts to automatically disappear after a certain amount of time. But those protections don't help as much if there's an underlying flaw in your device's operating system. And that's exactly what happened, and why Apple had to fix it.

On Wednesday, Apple released its latest minor update for iOS (and iPadOS). The release notes for iOS/iPadOS 26.4.2 show only one vulnerability patched by the new version. Impacting the notifications service on your iPhone or iPad, the note simply says: "Notifications marked for deletion could be unexpectedly retained on the device."

Also: What is Signal? 7 features that make it a go-to app for private, secure messaging

As is sometimes the case with Apple update notes, the explanation raises more questions than it answers. However, the reason for the update lies in the Signal app itself and in how the feds were able to skirt its security.

In a federal trial that concluded last month, several individuals were charged with and found guilty of setting off fireworks and vandalizing property at an ICE detention facility. One of the defendants, Lynette Sharp, had used Signal on her iPhone and later deleted the app, 404 Media (subscription required) reported earlier this month, citing people present at the trial.

How the FBI accessed Signal messages

During the trial, however, an FBI agent testified that the agency was able to access Sharp's incoming Signal messages because copies of their content had been saved on her phone's push notification database.

Normally, a message received via Signal triggers a push notification on your phone. The notification alerts you to the message and, by default, displays the name of the sender and shows some of the message content. In Signal, you can modify this option so that only the person's name appears, or that no name and no content appear.

Also: Apple's iOS 26.4.1 update enables Stolen Device Protection by default now - grab it today

Apparently, Sharp had left the default Signal notification settings unchanged. That meant the names and partial contents of texts she received (but not those she had sent) were still stored and accessible due to this iOS weakness. That weakness allowed the FBI to retrieve certain texts she had received on her phone.

"We learned that specifically on iPhones, if one's settings in the Signal app allow for message notifications and previews to show up on the lock screen, the iPhone will internally store those notifications/message previews in the internal memory of the device," a supporter of the defendants who was taking notes during the trial told 404 Media.

Though Apple has so far not acknowledged the Signal incident as the reason for iOS 26.4.2, Signal was open about it. In a post on X, Signal thanked Apple for the patch and specifically cited the FBI's access to message notification content even though the app had been deleted.

No user action required

"Apple's advisory confirmed that the bugs that allowed this to happen have been fixed in the latest iOS release," Signal said in its post. "Note that no action is needed for this fix to protect Signal users on iOS. Once you install the patch, all inadvertently preserved notifications will be deleted, and no forthcoming notifications will be preserved for deleted applications. We're grateful to Apple for the quick action here, and for understanding and acting on the stakes of this kind of issue."

Also: These warning signs could mean spyware is on your phone - and 9 ways to keep it secure

Though the patch may have been rolled out in response to the Signal incident, the update will presumably prevent the flaw from affecting other messaging apps. To get this latest update on your iPhone or iPad, head to Settings, select General, tap Software Updates, and then tap the button to update now. After the update is installed, restart your iPhone or iPad.

Security