Apple Fixes Critical Signal Message Recovery Vulnerability in iOS 26.4.2 Update
Apple has released a security update for iOS addressing a vulnerability that could allow deleted Signal messages to remain accessible on iPhones. The flaw, identified in the operating system’s handling of app data retention, potentially exposed messages users believed had been permanently erased from the Signal encrypted messaging app. The issue stemmed from how iOS managed temporary storage and cache files associated with Signal, where remnants of deleted conversations could persist in system logs or backup mechanisms even after users initiated deletion within the app. Security researchers noted that while Signal’s end-to-end encryption protects message content in transit and on its own servers, the vulnerability lay in the interaction between the app and iOS’s local data handling processes. Apple confirmed the fix in iOS 26.4.2, released earlier this week, which patches the specific data retention pathway that could allow recovery of deleted Signal messages through local device analysis. The update modifies how the operating system handles app-specific cache and temporary files, ensuring stricter adherence to deletion requests from third-party applications like Signal. Signal has not issued a public statement regarding the vulnerability, and Apple did not disclose whether any instances of exploitation were detected in the wild. The company typically reserves such details for cases involving active, widespread threats. Users are advised to update their devices to iOS 26.4.2 or later to apply the patch. The update is available through the Settings app under General > Software Update. Apple continues to recommend enabling automatic updates to ensure timely receipt of security fixes.