iOS 26.4.2: Closing the Notification Leak the FBI Exploited
Apple's April 22 patch fixes a single CVE โ but it's the one 404 Media reported the FBI was using to pull deleted Signal messages out of the iPhone's notification database.
Apple's April 22 patch fixes a single CVE โ but it's the one 404 Media reported the FBI was using to pull deleted Signal messages out of the iPhone's notification database.
Apple's iOS 26.4.1 fixes a CloudKit syncing regression that silently broke data sync across iPhones and iPads โ including the Passwords app โ while extending Stolen Device Protection to enterprise devices.
Apple's iOS 26.4 patches 37 security vulnerabilities โ including a Stolen Device Protection bypass and a Keychain access flaw โ while enabling Stolen Device Protection by default for all iPhones.
If your iPhone or Mac updated itself overnight without a full version bump, you just experienced Apple's first Background Security Improvement โ a quiet replacement for the failed Rapid Security Responses.
Apple's iOS 26.3.1 is a minor maintenance release timed to the March hardware event โ adding support for the iPhone 17e and new Studio Displays, with unspecified bug fixes and no security patches.
Apple's iOS 26.3 patches 40 security vulnerabilities including an actively exploited spyware zero-day, adds a first-party Transfer to Android migration tool built for EU compliance, and opens iPhone notifications to third-party wearables in Europe.