CVE-2026-28950
published 2026-04-22CVE-2026-28950: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and…
PriorityP335medium6.2CVSS 3.1
AVLACLPRNUINSUCHINAN
EPSS
2.88%
85.4th percentile
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly retained on the device.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 15.8.8 | 15.8.8 |
| apple | ios_and_ipados | < 16.7.16 | 16.7.16 |
| apple | ios_and_ipados | < 18.7.8 | 18.7.8 |
| apple | ios_and_ipados | < 26.4.2 | 26.4.2 |
| apple | ipados | < 17.7.11 | 17.7.11 |
| apple | ipados | < 18.7.8 | 18.7.8 |
| apple | ipados | >= 26.0 < 26.4.2 | 26.4.2 |
| apple | iphone_os | < 18.7.8 | 18.7.8 |
| apple | iphone_os | >= 26.0 < 26.4.2 | 26.4.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3hwj-7r29-g5vv: A logging issue was addressed with improved data redaction
ghsa_unreviewed·2026-04-22
CVE-2026-28950 [MEDIUM] CWE-359 GHSA-3hwj-7r29-g5vv: A logging issue was addressed with improved data redaction
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2. Notifications marked for deletion could be unexpectedly retained on the device.
VulDB
Apple iOS/iPadOS up to 18.7.7/26.4.1 Notifications log file
vuldb·2026-04-22
CVE-2026-28950 [LOW] Apple iOS/iPadOS up to 18.7.7/26.4.1 Notifications log file
A vulnerability classified as problematic has been found in Apple iOS and iPadOS up to 18.7.7/26.4.1. This vulnerability affects unknown code of the component Notifications Handler. Performing a manipulation results in sensitive information in log files.
This vulnerability was named CVE-2026-28950. The attack needs to be approached locally. There is no available exploit.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Checkpoint
27th April – Threat Intelligence Report
blogs_checkpoint·2026-04-27
CVE-2025-55182 27th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th April, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Vercel, a frontend cloud platform, has disclosed a security incident linked to a compromise at Context.ai, where stolen OAuth tokens enabled unauthorized access through a connected app. The company reported access to employee information, internal logs, and a subset of environment variables, while stating that the most sensiti
Sans Isc
Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)
blogs_sans_isc·2026-04-23
CVE-2026-28950 Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)
Apple Patches Exploited Notification Flaw
Published: 2026-04-23. Last Updated: 2026-04-23 10:18:30 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
Apple yesterday released iOS/iPadOS 26.4.2 and iOS/iPadOS 18.7.8. This update fixes a single Notification Services vulnerability, CVE-2026-28950:
Impact: Notifications marked for deletion could be unexpectedly retained on the device
Description: A logging issue was addressed with improved data redaction.
Apple did not mark the vulnerability as exploited. However, recent news articles reported that the FBI used this vulnerability to extract Signal messages from a device seized in a criminal case. The suspect in the case used Signal to communicate. Signal is encrypted end-to-end and attempts not to store retrievable data on the device
Hackernews
Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages
blogs_hackernews·2026-04-23
CVE-2026-28950 Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages
Apple has rolled out a software fix for iOS and iPadOS to address a Notification Services flaw that stored notifications marked for deletion on the device.
The vulnerability, tracked as CVE-2026-28950 (CVSS score: N/A), has been described as a logging issue that has been addressed with improved data redaction.
"Notifications marked for deletion could be unexpectedly retained on the device," Apple said in an advisory.
The shortcoming affects the following devices -
iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generat
https://support.apple.com/en-us/127002https://support.apple.com/en-us/127003https://support.apple.com/en-us/127112https://support.apple.com/en-us/127113https://support.apple.com/en-us/127114http://seclists.org/fulldisclosure/2026/Apr/14http://seclists.org/fulldisclosure/2026/Apr/15http://seclists.org/fulldisclosure/2026/May/10http://seclists.org/fulldisclosure/2026/May/8http://seclists.org/fulldisclosure/2026/May/9
2026-04-22
Published