Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)
ID: 3eeaa8f1-0a6c-5f05-97d2-324507ce7b07
STIX ID: report--3eeaa8f1-0a6c-5f05-97d2-324507ce7b07
Feed Name: SANS ISC Diary
Threat Score
Apple released iOS/iPadOS 26.4.2 and 18.7.8 fixing CVE-2026-28950, a Notification Services bug where notifications marked for deletion could be unexpectedly retained and reveal message contents. While Apple did not declare the flaw as exploited, news reports claim the FBI leveraged it to extract Signal messages from a seized device, highlighting risks when secure apps rely on OS notification frameworks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
