Vulnerability intelligence
CVE-2026-28950
Apple iOS and iPadOS
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly retained on the device.
CVSS Score
6.2
Medium
EPSS — Exploit Probability
2.9%
Riskier than 86% of all CVEs · checked 2026-09-08
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
6 articles across 6 outlets · first covered Apr 23, 2026 · latest Apr 23, 2026
Coverage timeline
-
iOS Flaw Let Deleted Notifications Linger, Apple Issues Fixsecurityaffairs.com · Apr 23, 2026
-
Apple patches CVE-2026-28950 bug that kept deleted messageswww.infosecurity-magazine.com · Apr 23, 2026
-
Apple patches iOS bug CVE-2026-28950 exposing deleted alertswww.malwarebytes.com · Apr 23, 2026
-
Apple fixes iOS notification bug that exposed Signal chats to FBIisc.sans.edu · Apr 23, 2026
-
Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Casethehackernews.com · Apr 23, 2026
-
Apple patches iOS bug letting deleted Signal messages resurfacewww.securityweek.com · Apr 23, 2026