Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2685 articles · 122969 vulns · 36/41 feeds (7d)
← Back to list
6.2
CVE-2026-28950EXPLOITEDPATCHED
apple · ios

CVE-2026-28950: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and iPadOS 18.7.8, iOS 26.

Description

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2. Notifications marked for deletion could be unexpectedly retained on the device.

Affected Products

VendorProductVersions
appleiosunspecified, unspecified

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
appleipadoscert_advisory90%
appleioscert_advisory90%

References

  • https://support.apple.com/en-us/127003
  • https://support.apple.com/en-us/127002

Related News (11 articles)

Tier D
Help Net Security5h ago
Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach
→ No new info (linked only)
Tier D
Infosecurity Magazine3d ago
Apple Fixes iOS Notification Bug Exposing Deleted Messages
→ No new info (linked only)
Tier D
Help Net Security3d ago
Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950)
→ No new info (linked only)
Tier B
BSI Advisories3d ago
[NEU] [mittel] Apple iOS und iPadOS: Schwachstelle ermöglicht Offenlegung von Informationen
→ No new info (linked only)
Tier D
SecurityWeek3d ago
Apple Patches iOS Flaw Allowing Recovery of Deleted Chats
→ No new info (linked only)
Tier D
The Hacker News3d ago
Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Case
→ No new info (linked only)
Tier B
CERT-FR3d ago
Vulnérabilité dans les produits Apple (23 avril 2026)
→ No new info (linked only)
Tier D
BleepingComputer3d ago
Apple fixes iOS bug that retained deleted notification data
→ No new info (linked only)
Tier B
CCCS Canada3d ago
Apple security advisory (AV26-381)
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-28950 | Apple iOS/iPadOS up to 18.7.7/26.4.1 Notifications log file
→ No new info (linked only)
Tier B
BSI Advisories19d ago
[UPDATE] [hoch] Apple iOS und iPadOS: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.16.2 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
18.7.826.4.2
PublishedApr 22, 2026
Last enriched2d agov8
Tags
information disclosuredenial of servicesecurity bypassproblematiciosstate-sponsoredzero-click exploitUS governmenthacking toolsnotification servicesrecovery of deleted messagesforensic toolsprivacy concernsmobile data exposureforensic investigation
Trending Score78
Source articles11
Independent9
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20652
The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. A remote attacker ma
Trending: 23
MEDIUMCVE-2026-20635
The issue was addressed with improved memory handling. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 2
Trending: 20
MEDIUMCVE-2026-20636
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, Safari 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lea
Trending: 20
MEDIUMCVE-2026-20676
CVE-2026-20676: This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3
Trending: 20
MEDIUMCVE-2026-20644
The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. Processing malicious
Trending: 20

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 22, 2026
Discovered by ZDM
Apr 22, 2026
Updated: description, severity, cvssEstimate, affectedVersions, tags
Apr 22, 2026
Updated: affectedVersions
Apr 22, 2026
Updated: cweIds, tags
Apr 23, 2026
Updated: description, tags
Apr 23, 2026
Updated: description
Apr 23, 2026
Updated: tags
Apr 23, 2026
Updated: affectedVersions
Apr 23, 2026
Actively Exploited
Apr 23, 2026
Exploit Available
Apr 23, 2026
Patch Available
Apr 23, 2026

Version History

v8
Last enriched 2d ago
v8Tier B2d ago

Updated affected versions to include all versions prior to 18.7.8 and 26.4.2, and set patchAvailable to null.

affectedVersions
via CERT-FR
v7Tier D2d ago

Added affected version 26.4.2 and new tags related to privacy concerns and forensic investigation.

tags
via Infosecurity Magazine
v6Tier D3d ago

Updated description with more technical detail about the logging issue and added 'notification services' as a new tag.

description
via Help Net Security
v5Tier D3d ago

Updated description with more technical detail, added affected version 26.4.2, and included new tags related to the vulnerability.

descriptiontags
via SecurityWeek
v4Tier D3d ago

Updated description with more technical detail, added CWE-200, and included new tag 'notification services'.

cweIdstags
via The Hacker News
v3Tier B3d ago

Updated affected versions to include 26.4.2 and set patchAvailable to null.

affectedVersions
via CCCS Canada
v2Tier C3d ago

Updated description with technical details, changed severity to HIGH, and added affected versions 18.7.7 and 26.4.1.

descriptionseveritycvssEstimateaffectedVersionstags
via VulDB
v13d ago

Initial creation