Threat reportVulnerabilityTL-2026-0413

Apple iOS/iPadOS Notification Services Data Retention Zero-Day (CVE-2026-28950) — Exploited In-The-Wild for Forensic Extraction of Signal Messages

highMONITORING

Apple iOS/iPadOS Notification Services Data Retention (TL-2026-0413), also tracked as Apple Notification Retention Flaw, is a high-severity software vulnerability scored CVSS 5.5, first published 2026-04-23. It is attributed to U.S. Federal Bureau of Investigation forensic examiners (United States) with medium confidence, affects Apple iOS, references 1 CVE (CVE-2026-28950), maps to 15 MITRE ATT&CK techniques (T1005, T1052.001, T1070), and is covered by 9 detection rules and 21 indicators of compromise.

CVSS
5.5/10High
CVEs
1Referenced vulnerabilities
Techniques
15MITRE ATT&CK
Actors
1U.S. Federal Bureau of Investigation forensic examiners
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-0413

Threat ID
TL-2026-0413
Also known as
Apple Notification Retention Flaw, iOS Notification Logging Leak, Signal-on-iOS Forensic Extraction Bug
Severity
HIGH
CVSS
5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution
U.S. Federal Bureau of Investigation forensic examiners
Attribution confidence
MEDIUM
Nation-state nexus
United States
Motivation
ESPIONAGE
Target sectors
government, legal, journalism, civil-society, financial, healthcare, technology, defense, dissidents, executives
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
21

Malware and tooling in Apple iOS/iPadOS Notification Services Data Retention

Malware and tooling: Cellebrite UFED Premium, MSAB XRY, Magnet GRAYKEY, iLEAPP (iOS Logs, Events, And Plists Parser)

How Apple iOS/iPadOS Notification Services Data Retention works

Apple issued emergency out-of-band updates iOS/iPadOS 26.4.2 and 18.7.8 on 2026-04-22 to fix CVE-2026-28950, a Notification Services logging flaw in which notifications marked for deletion were unexpectedly retained on-device in plaintext. The flaw was reportedly exploited in-the-wild by the FBI to extract Signal message content (sender usernames and partial message bodies) from a seized iPhone during a criminal investigation. Apple addressed the issue through improved data redaction.

CVE-2026-28950 is a logging and data-retention flaw in the Apple Notification Services (UserNotifications / apsd / duetexpertd) subsystem that affects iOS, iPadOS, and derivatives prior to 18.7.8 (legacy branch) and 26.4.2 (current branch). When the user — or an application programmatically — dismisses a notification, the notification payload is supposed to be removed from persistent storage. Apple's disclosure states the underlying bug was a logging issue: the notification content (including the delivered body text, sender identifier, bundle identifier, and metadata) was written to on-device diagnostic / CoreDuet-style stores without being redacted when the notification was dismissed. As a result, an attacker with physical access to the device and the ability to extract user partition contents (for example through a forensic unlocking tool such as Cellebrite UFED Premium or Magnet GRAYKEY, or through a checkm8-class bootrom exploit on pre-A12 hardware) could recover notifications the user believed had been deleted, including end-to-end-encrypted secure-messenger content surfaced via the extension-delivered push payload (Signal, WhatsApp, iMessage, Telegram notifications).

The public trigger for the emergency patch is a filing in an ongoing U.S. federal criminal investigation in which FBI forensic examiners recovered the contents of Signal notifications — specifically sender usernames and partial message bodies — from a seized iPhone running a pre-patch iOS release. Because Signal delivers notification payloads via the Apple Push Notification Service and then decrypts them inside a Notification Service Extension before the system renders them to the user, the plaintext decrypted body transits the UserNotifications subsystem — which is exactly where this flaw caused data to be retained. This means a privacy property users and defenders reasonably relied on ("dismissed secure-messenger notifications leave no content on disk") was false across the affected OS range.

The attack vector is LOCAL / PHYSICAL: no network exploitation, no remote code execution, no elevation of privilege. However, the value of the retained data is high because (a) it includes end-to-end-encrypted messenger content users considered ephemeral, (b) it includes authentication codes and one-time passwords delivered via push notifications, and (c) it is accessible to any party that can perform a user-partition forensic extraction — including law enforcement using commercially available tooling, border / customs authorities, hostile insiders, and thieves or intimate-partner-surveillance actors with access to unlock the device. Apple rates the issue as warranting an out-of-band patch, which historically correlates with active exploitation.

Affected versions: iOS 26.0 through 26.4.1, iPadOS 26.0 through 26.4.1, iOS 18.0 through 18.7.7, and iPadOS 18.0 through 18.7.7 (legacy hardware branch). The patch ships as iOS/iPadOS 26.4.2 (build 23F77, current branch) and iOS/iPadOS 18.7.8 (build 22H305, legacy branch covering iPhone XS/XR and older). Apple's fix note describes the remediation as "improved data redaction" — indicating the logging path that received notification content now applies redaction before persisting, rather than storing the raw payload. Defenders should deploy the update via MDM immediately to all managed Apple mobile fleets, and — for high-risk principals — wipe and restore devices that were unlocked and out of physical control during the vulnerable period, because the retained data remains on disk even after patching.

MITRE ATT&CK techniques used in TL-2026-0413

Collection

T1005 Data from Local System; T1074.001 Data Staged: Local Data Staging; T1119 Automated Collection; T1213 Data from Information Repositories

Exfiltration

T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB

Defense Evasion

T1070 Indicator Removal; T1070.004 File Deletion

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

Initial Access

T1200 Hardware Additions

Credential Access

T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1555 Credentials from Password Stores

Impact

T1565 Data Manipulation

Affected products and versions in Apple iOS/iPadOS Notification Services Data Retention

  • Apple — iOS
    Vulnerable versions: 26.0; 26.0.1; 26.1; 26.2; 26.3; 26.3.1; 26.4; 26.4.1
    Fixed in: 26.4.2
  • Apple — iPadOS
    Vulnerable versions: 26.0; 26.0.1; 26.1; 26.2; 26.3; 26.3.1; 26.4; 26.4.1
    Fixed in: 26.4.2
  • Apple — iOS (legacy branch)
    Vulnerable versions: 18.0; 18.1; 18.2; 18.3; 18.4; 18.5; 18.6; 18.7; 18.7.1; 18.7.2
    Fixed in: 18.7.8
  • Apple — iPadOS (legacy branch)
    Vulnerable versions: 18.0; 18.1; 18.2; 18.3; 18.4; 18.5; 18.6; 18.7; 18.7.1; 18.7.2
    Fixed in: 18.7.8

Remediation for Apple iOS/iPadOS Notification Services Data Retention

Patches

  • iOS 26.4.2 (build 23F77) — https://support.apple.com/en-us/127002
  • iPadOS 26.4.2 (build 23F77) — https://support.apple.com/en-us/127002
  • iOS 18.7.8 (build 22H305, legacy devices) — https://support.apple.com/en-us/127003
  • iPadOS 18.7.8 (build 22H305, legacy devices) — https://support.apple.com/en-us/127003

Immediate actions

  • Push iOS 26.4.2 / iPadOS 26.4.2 to all current-branch managed devices via MDM (Jamf, Intune, Kandji, Mosyle) with an enforced install deadline of 24 hours.
  • Push iOS 18.7.8 / iPadOS 18.7.8 to all legacy-branch managed devices (iPhone XS / XR / older, iPad 7 and older).
  • Identify VIP / high-risk principals (executives, journalists, dissidents, legal, security staff) whose devices may have been physically out of their control in the last 180 days and wipe-and-restore those devices after patching to remove retained notification data.
  • Disable Lock Screen and Notification Center previews for Signal, WhatsApp, iMessage, and other secure messengers via Settings -> Notifications -> Show Previews: Never.
  • Audit and rotate any one-time-password and MFA tokens that were delivered via push notification during the vulnerable window on affected devices.

Workarounds

  • Until patched, disable notification previews globally (Settings -> Notifications -> Show Previews: Never) to reduce the content that transits UserNotifications and can be retained.
  • For Signal specifically, toggle Signal -> Settings -> Notifications -> Show: No Name or Content so the decrypted body never populates the notification payload.
  • Enforce iPhone USB Restricted Mode (Settings -> Face ID & Passcode -> USB Accessories: Off) so that locked devices refuse USB data connections, blunting forensic-tool attach.
  • Use longer alphanumeric passcodes (>= 8 chars, alphanumeric) to materially slow brute-force by forensic unlocking tools.

Longer-term hardening

  • Establish MDM posture that blocks enrollment / conditional access for devices running iOS/iPadOS below 18.7.8 or 26.4.2.
  • For high-threat users, migrate MFA delivery off SMS and push-notification channels onto hardware FIDO2 authenticators (YubiKey, Titan) so that intercepted notifications cannot leak active authentication material.
  • Deploy mobile threat defense (Lookout, Zimperium, Jamf Protect) to alert on devices that fall behind patch baseline or exhibit signs of forensic extraction (jailbreak indicators, unusual USB activity).
  • Document in the threat model that secure-messenger notification previews are extracted by forensic tooling until the device is wiped post-patch; treat pre-patch notification history as potentially compromised.
  • Adopt organizational policy that business devices crossing borders or entering hostile custody are wiped and re-provisioned rather than trusted after return.

CVEs associated with Apple iOS/iPadOS Notification Services Data Retention

CVE-2026-28950

Weaknesses (CWE) in Apple iOS/iPadOS Notification Services Data Retention

CWE-532, CWE-312, CWE-359, CWE-922

Timeline of Apple iOS/iPadOS Notification Services Data Retention

  • Regression in the UserNotifications diagnostic logging path is believed to have been introduced in the iOS/iPadOS 18.x and 26.x development branches; dismissed-notification payloads begin persisting to disk without redaction (approximate date inferred from version ranges listed in Apple advisory).
  • FBI Computer Analysis Response Team forensic examiners reportedly recover Signal notification content (sender usernames and partial message bodies) from a seized iPhone during a federal criminal investigation, demonstrating in-the-wild exploitation of CVE-2026-28950 via forensic extraction.
  • Vulnerability reported to Apple product-security@apple.com by an external party after the forensic artifact was surfaced in legal filings and cross-referenced to an unpatched iOS version.
  • CVE-2026-28950 is assigned and published by Apple product-security@apple.com with sources https://support.apple.com/en-us/127002 and https://support.apple.com/en-us/127003.
  • Apple publishes emergency out-of-band updates iOS/iPadOS 26.4.2 (current branch) and iOS/iPadOS 18.7.8 (legacy branch) addressing CVE-2026-28950 with 'improved data redaction'. CVE is also published to NVD.
  • Threadlinqs Intelligence publishes TL-2026-0413 with full D1-aligned research, MITRE mapping, detections, and simulations to support defender patch enforcement and forensic posture remediation.
  • SANS Internet Storm Center publishes diary entry 32922 analysing the out-of-band patch and highlighting the Signal-notification-extraction use case; cross-industry advisories begin.
  • As of 2026-05-29, CVE-2026-28950 was patched by Apple on 2026-04-22 (iOS/iPadOS 26.4.2, 18.7.8, plus 15-17 backports) with improved data redaction that also purges retained notifications, and it is not in CISA KEV. It remains exploitable on unpatched/legacy devices via physical access and forensic tooling (Cellebrite/GRAYKEY), so the local extraction technique persists.

Sources cited for Apple iOS/iPadOS Notification Services Data Retention

Detection coverage for TL-2026-0413

As of 2026-04-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0413 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats