Apple iOS/iPadOS Notification Services Data Retention Zero-Day (CVE-2026-28950) — Exploited In-The-Wild for Forensic Extraction of Signal Messages — Threadlinqs Intelligence
As of 2026-05-30, Apple iOS/iPadOS Notification Services Data Retention Zero-Day (CVE-2026-28950) — Exploited In-The-Wild for Forensic Extraction of Signal Messages is a high-severity vulnerability threat attributed to U.S. Federal Bureau of Investigation forensic examiners (United States), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0413 · Severity: HIGH · CVSS: 5.5 · Status: MONITORING · Category: VULNERABILITY
Attribution: U.S. Federal Bureau of Investigation forensic examiners · United States · ESPIONAGE
Apple issued emergency out-of-band updates iOS/iPadOS 26.4.2 and 18.7.8 on 2026-04-22 to fix CVE-2026-28950, a Notification Services logging flaw in which notifications marked for deletion were
CVE-2026-28950 is a logging and data-retention flaw in the Apple Notification Services (UserNotifications / apsd / duetexpertd) subsystem that affects iOS, iPadOS, and derivatives prior to 18.7.8 (legacy branch) and 26.4.2 (current branch). When the user — or an application programmatically — dismisses a notification, the notification payload is supposed to be removed from persistent storage. Apple's disclosure states the underlying bug was a logging issue: the notification content (including the delivered body text, sender identifier, bundle identifier, and metadata) was written to on-device diagnostic / CoreDuet-style stores without being redacted when the notification was dismissed. As a result, an attacker with physical access to the device and the ability to extract user partition contents (for example through a forensic unlocking tool such as Cellebrite UFED Premium or Magnet GRAYKEY, or through a checkm8-class bootrom exploit on pre-A12 hardware) could recover notifications the user believed had been deleted, including end-to-end-encrypted secure-messenger content surfaced via the extension-delivered push payload (Signal, WhatsApp, iMessage, Telegram notifications).
The public trigger for the emergency patch is a filing in an ongoing U.S. federal criminal investigation in which FBI forensic examiners recovered the contents of Signal notifications — specifically sender usernames and partial message bodies — from a seized iPhone running a pre-patch iOS release. Because Signal delivers notification payloads via the Apple Push Notification Service and then decrypts them inside a Notification Service Extension before the system renders them to the user, the plaintext decrypted body transits the UserNotifications subsystem — which is exactly where this flaw caused data to be retained. This means a privacy property users and defenders reasonably relied on ("dismissed secure-messenger notifications leave no content on disk") was false across the affected OS range.
The attack vector is LOCAL / PHYSICAL: no network exploitation, no remote code execution, no elevation of privilege. However, the value of the retained data is high because (a) it includes end-to-end-encrypted messenger content users considered ephemeral, (b) it includes authentication codes and one-time passwords delivered via push notifications, and (c) it is accessible to any party that can perform a user-partition forensic extraction — including law enforcement using commercially available tooling, border / customs authorities, hostile insiders, and thieves or intimate-partner-surveillance actors with access to unlock the device. Apple rates the issue as warranting an out-of-band patch, which historically correlates with active exploitation.
Affected versions: iOS 26.0 through 26.4.1, iPadOS 26.0 through 26.4.1, iOS 18.0 through 18.7.7, and iPadOS 18.0 through 18.7.7 (legacy hardware branch). The patch ships as iOS/iPadOS 26.4.2 (build 23F77, current branch) and iOS/iPadOS 18.7.8 (build 22H305, legacy branch covering iPhone XS/XR and older). Apple's fix note describes the remediation as "improved data redaction" — indicating the logging path that received notification content now applies redaction before persisting, rather than storing the raw payload. Defenders should deploy the update via MDM immediately to all managed Apple mobile fleets, and — for high-risk principals — wipe and restore devices that were unlocked and out of physical control during the vulnerable period, because the retained data remains on disk even after patching.
Weaknesses (CWE)
CWE-532, CWE-312, CWE-359, CWE-922
Target sectors: government, legal, journalism, civil-society, financial, healthcare, technology, defense, dissidents, executives
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-28950, T1005, T1213, T1119, T1074.001, T1552.001, T1555, T1528, T1083, T1087, T1082