Junglewise Threat Intelligence

CVE-2026-28950: Apple iOS and iPadOS improper data redaction in Notification Services

CVE-2026-28950 · Severity: medium · CVSS 6.2 · Published 2026-04-22

Technologies: Apple iPadOS. Vendors: Apple.

Executive brief

A security issue in Apple's mobile operating systems could cause sensitive notifications to remain on a device even after a user has deleted them. This occurs due to improper data handling in the system's logging services, potentially allowing someone with access to the device to view private information that was intended to be removed. Users should update to the latest software versions to ensure deleted data is properly redacted and removed.

Technical details

A logging vulnerability (CWE-359) exists in Apple iOS and iPadOS Notification Services due to insufficient data redaction. The flaw allows notifications that have been marked for deletion by the user or system to persist in system logs or storage rather than being purged. An attacker with local access to the device could potentially recover and view these retained notifications, leading to the exposure of private personal information. The issue was addressed by improving data redaction logic within the logging component. Patches are available in iOS/iPadOS 15.8.8, 16.7.16, 18.7.8, 26.4.2, and iPadOS 17.7.11.

Affected products

  • Apple iOS versions up to 15.8.8, 16.7.16, 18.7.8, 26.4.2
  • Apple iPadOS versions up to 15.8.8, 16.7.16, 17.7.11, 18.7.8, 26.4.2

Timeline

  • 2026-04-22: disclosed
  • 2026-04-22: advisory
  • 2026-04-22: patched
  • 2026-05-11: other: Advisory updated with additional affected versions

References

Related threats