Apple releases iOS 26.4.2 to eliminate notification cache data retention

Apple logo

Apple logo - Michael Derrer Fuchs / Shutterstock.com

Apple released iOS 26.4.2 and iPadOS 26.4.2 versions this Wednesday to fix a security vulnerability in the notification system. The problem allowed fragments of messages to remain stored in the device’s cache even after the user deleted them. The flaw, identified as CVE-2026-28950, mainly affected users of messaging applications with end-to-end encryption, such as Signal. Dispositivos with older models receive iOS 18.7.8 and iPadOS 18.7.8 with the same fix.

Como flaw exposed notification data

The error occurred in the iOS internal push notification database. Quando a user received an encrypted message, the system generated a preview on the lock screen for notification. Mesmo after the user deleted the message or uninstalled the application, excerpts of text from this preview remained stored in the device’s local memory.

iOS 26 – jackpress/shutterstock.com

Ferramentas specialized forensics, such as Cellebrite and GrayKey, were able to recover these text fragments without accessing the application itself. The case gained visibility after a report on an FBI investigation into Texas in July 2025, when agents managed to retrieve messages from an encrypted communication app through the operating system’s cache. The application’s end-to-end encryption remained intact, but access to the cache bypassed this protection.

  • Notificações of received messages automatically generated stored previews.
  • Exclusão manual in the app did not completely clear the operating system cache.
  • Ferramentas forensics extracted retained data without breaking application encryption.
  • The problem only affected push notification content, not sent messages.
  • Antes of the fix, disabling previews was the only effective way to avoid retention.

Solução implemented by Apple

Apple solved the problem with more robust data hygiene at the operating system level. iOS 26.4.2 now reliably removes information from notifications as soon as they are marked for deletion. The change occurs automatically without requiring changes to users’ habits or additional configuration.

Usuários that had previews enabled gain automatic protection with the update. Antes, the only effective way to avoid retention was to manually disable the feature in the device settings. Apple’s official documentation only mentions the technical fix described as “improved data redaction on a registry issue”, without detailing previous exploitation or ongoing investigations.

Dispositivos Compatibles and Installation Process

Modelos from iPhone 11 onwards receive iOS 26.4.2 with build 23E261. The list of compatible iPads includes third-generation iPad Pro, third-generation iPad Air, eighth-generation iPad, and fifth-generation iPad mini. Todos receive iPadOS 26.4.2 with the same build. Versões older iPhone and iPad get iOS 18.7.8 and iPadOS 18.7.8 with build 22H352.

Installation takes place via the Ajustes app. Usuários must access Geral, then Atualização from Software, where the system checks availability and starts the download. The process takes a few minutes and requires a stable internet connection. The device may restart during installation, but no personal data is erased. Especialistas recommend updating as soon as possible, especially for those who use apps with temporary or encrypted messages.

Impacto for messaging app users

The adjustment mainly benefits those who receive notifications with text content in communication apps. Aplicativos and Signal, which offer automatic message deletion, now have more effective cleaning on iOS. Fragmentos that were previously retained in the system cache should no longer persist after the update.

The change reinforces local privacy without interfering with applications’ end-to-end encryption. Usuários does not need to disable previews to maintain security, as the operating system takes care of removal automatically. Apple maintains a policy of not discussing vulnerabilities until patches are released, and official support only lists the technical description of the resolved issue.

Cronograma release and upcoming updates

Updates are available via over-the-air download in all markets. Dispositivos with automatic updates enabled should receive the package soon. The launch comes as Apple prepares the next major version of the system, with iOS 26.5 beta testing underway and WWDC 2026 approaching. The security patch arrives independently to urgently protect current devices, demonstrating the company’s attention to information retention issues even in scenarios of intentional user deletion.

See Also