Apps & Consumer
Apple patches bug that exposed deleted messages to law enforcement
Apple released a software update fixing a bug that allowed law enforcement to access deleted messages by retrieving cached notification data stored on iPhones and iPads.
Apple released a software update on Wednesday for iPhones and iPads to resolve a security vulnerability that allowed law enforcement to extract messages that had been deleted or disappeared. The company also backported the fix—meaning it applied the software fix to an older version of the software—for iPhone and iPad owners running the older iOS 18 software. This vulnerability was a bug that cops used to extract deleted chat messages from iPhones, bypassing the standard privacy protections of encrypted messaging applications.
The vulnerability stemmed from a bug where notifications containing message content were cached on the device for up to a month. In a security notice on its website, Apple acknowledged the flaw, stating that notifications marked for deletion could be unexpectedly retained on the device. This caching meant that even if a user set their messaging app to automatically delete or disappear messages, the operating system’s notification database continued to store the text of those notifications on the physical device.
This database logging directly conflicted with the privacy features of secure communications tools. Signal, like other messaging apps such as WhatsApp, allows users to set up a timer that instructs the app to automatically delete messages after a set amount of time. This feature is designed to keep conversations private if a device is seized, but the operating system’s notification cache undermined this protocol by keeping a local copy of the message text.
The issue was brought to light earlier this month by 404 Media, an independent news outlet. 404 Media reported that the FBI had been able to extract deleted Signal messages from someone’s iPhone using forensic tools—which are software or hardware used by law enforcement to extract data from devices. The extraction was possible because the message content had been displayed in a notification and subsequently stored in the device’s database, despite being deleted within the Signal app itself. Following the report, Signal president Meredith Whittaker publicly urged Apple to resolve the flaw, writing on the social media platform Bluesky that “Notifications for deleted messages shouldn’t remain in any OS notification database”.
Why it matters
This fix addresses a critical vulnerability where device-level notification logging undermined user-set privacy features like auto-delete, highlighting the tension between OS-level data retention and encrypted messaging security.