# Apple iOS/iPadOS Notification Services Data Retention Zero-Day (CVE-2026-28950) — Exploited In-The-Wild for Forensic Extraction of Signal Messages

> Apple issued emergency out-of-band updates iOS/iPadOS 26.4.2 and 18.7.8 on 2026-04-22 to fix CVE-2026-28950, a Notification Services logging flaw in which notifications marked for deletion were unexpectedly retained on-device in plaintext. The flaw was reportedly exploited in-the-wild by the FBI to extract Signal message content (sender usernames and partial message bodies) from a seized iPhone during a criminal investigation. Apple addressed the issue through improved data redaction.

- **Published:** 2026-04-23T12:00:00Z
- **Last reviewed:** 2026-04-23T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0413
- **ID:** TL-2026-0413
- **Severity:** HIGH (CVSS 5.5)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Actor:** U.S. Federal Bureau of Investigation forensic examiners (United States)
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-28950

## Description

CVE-2026-28950 is a logging and data-retention flaw in the Apple Notification Services (UserNotifications / apsd / duetexpertd) subsystem that affects iOS, iPadOS, and derivatives prior to 18.7.8 (legacy branch) and 26.4.2 (current branch). When the user — or an application programmatically — dismisses a notification, the notification payload is supposed to be removed from persistent storage. Apple's disclosure states the underlying bug was a logging issue: the notification content (including the delivered body text, sender identifier, bundle identifier, and metadata) was written to on-device diagnostic / CoreDuet-style stores without being redacted when the notification was dismissed. As a result, an attacker with physical access to the device and the ability to extract user partition contents (for example through a forensic unlocking tool such as Cellebrite UFED Premium or Magnet GRAYKEY, or through a checkm8-class bootrom exploit on pre-A12 hardware) could recover notifications the user believed had been deleted, including end-to-end-encrypted secure-messenger content surfaced via the extension-delivered push payload (Signal, WhatsApp, iMessage, Telegram notifications).

The public trigger for the emergency patch is a filing in an ongoing U.S. federal criminal investigation in which FBI forensic examiners recovered the contents of Signal notifications — specifically sender usernames and partial message bodies — from a seized iPhone running a pre-patch iOS release. Because Signal delivers notification payloads via the Apple Push Notification Service and then decrypts them inside a Notification Service Extension before the system renders them to the user, the plaintext decrypted body transits the UserNotifications subsystem — which is exactly where this flaw caused data to be retained. This means a privacy property users and defenders reasonably relied on ("dismissed secure-messenger notifications leave no content on disk") was false across the affected OS range.

The attack vector is LOCAL / PHYSICAL: no network exploitation, no remote code execution, no elevation of privilege. However, the value of the retained data is high because (a) it includes end-to-end-encrypted messenger content users considered ephemeral, (b) it includes authentication codes and one-time passwords delivered via push notifications, and (c) it is accessible to any party that can perform a user-partition forensic extraction — including law enforcement using commercially available tooling, border / customs authorities, hostile insiders, and thieves or intimate-partner-surveillance actors with access to unlock the device. Apple rates the issue as warranting an out-of-band patch, which historically correlates with active exploitation.

Affected versions: iOS 26.0 through 26.4.1, iPadOS 26.0 through 26.4.1, iOS 18.0 through 18.7.7, and iPadOS 18.0 through 18.7.7 (legacy hardware branch). The patch ships as iOS/iPadOS 26.4.2 (build 23F77, current branch) and iOS/iPadOS 18.7.8 (build 22H305, legacy branch covering iPhone XS/XR and older). Apple's fix note describes the remediation as "improved data redaction" — indicating the logging path that received notification content now applies redaction before persisting, rather than storing the raw payload. Defenders should deploy the update via MDM immediately to all managed Apple mobile fleets, and — for high-risk principals — wipe and restore devices that were unlocked and out of physical control during the vulnerable period, because the retained data remains on disk even after patching.

## MITRE ATT&CK

- T1005 Data from Local System
- T1213 Data from Information Repositories
- T1119 Automated Collection
- T1074.001 Data Staged: Local Data Staging
- T1552.001 Unsecured Credentials: Credentials In Files
- T1555 Credentials from Password Stores
- T1528 Steal Application Access Token
- T1083 File and Directory Discovery
- T1087 Account Discovery
- T1082 System Information Discovery
- T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB
- T1070.004 File Deletion
- T1070 Indicator Removal
- T1200 Hardware Additions
- T1565 Data Manipulation

## Sources

- [SANS ISC Diary: Apple Patches Exploited Notification Flaw](https://isc.sans.edu/diary/rss/32922)
- [Apple Security Release — iOS 26.4.2 and iPadOS 26.4.2](https://support.apple.com/en-us/127002)
- [Apple Security Release — iOS 18.7.8 and iPadOS 18.7.8](https://support.apple.com/en-us/127003)
- [NVD — CVE-2026-28950](https://nvd.nist.gov/vuln/detail/CVE-2026-28950)
- [Apple Security Updates Index (HT201222)](https://support.apple.com/en-us/HT201222)
- [CWE-532: Insertion of Sensitive Information into Log File](https://cwe.mitre.org/data/definitions/532.html)
- [MITRE ATT&CK T1005 Data from Local System](https://attack.mitre.org/techniques/T1005/)
- [MITRE ATT&CK T1552.001 Unsecured Credentials: Credentials In Files](https://attack.mitre.org/techniques/T1552/001/)
- [Signal Docs — iOS Notification Service Extension behaviour](https://github.com/signalapp/Signal-iOS)
- [Cellebrite UFED Premium — supported iOS forensic extractions](https://cellebrite.com/en/ufed/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0413
