logo

Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)

ID: 3eeaa8f1-0a6c-5f05-97d2-324507ce7b07

STIX ID: report--3eeaa8f1-0a6c-5f05-97d2-324507ce7b07

Feed Name: SANS ISC Diary

Threat Score
50/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

...
...

Apple released iOS/iPadOS 26.4.2 and 18.7.8 fixing CVE-2026-28950, a Notification Services bug where notifications marked for deletion could be unexpectedly retained and reveal message contents. While Apple did not declare the flaw as exploited, news reports claim the FBI leveraged it to extract Signal messages from a seized device, highlighting risks when secure apps rely on OS notification frameworks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.