:

APPLE FIXES BUG THAT LET POLICE ACCESS DELETED SIGNAL CHATS

INDUSTRY DESK2 MIN READ
THU, APR 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Apple has patched a vulnerability that retained Signal message data even after users deleted the app, potentially allowing law enforcement to access private communications. Signal confirmed the fix resolves the security issue.

Apple discovered and fixed a bug in iOS that cached Signal chat data in a way that persisted after users uninstalled the messaging app. The cached files could theoretically be accessed by authorities during device searches, creating an unexpected privacy vulnerability for Signal users. Signal, the encrypted messaging platform favored by privacy advocates and journalists, expressed satisfaction with Apple's remediation. The open-source messaging app relies on end-to-end encryption to prevent interception of communications, but the iOS caching issue created a backdoor of sorts—not through Signal's encryption, but through Apple's operating system. The bug affected how iOS managed temporary data and cache files associated with third-party applications. When Signal was deleted, fragments of chat data remained on the device in locations accessible to forensic tools commonly used by law enforcement and intelligence agencies. Apple did not publicly disclose the vulnerability before patching it, which is standard practice for security fixes. The company typically addresses such issues silently through regular iOS updates to avoid alerting bad actors to exploitable gaps. The incident highlights the complex intersection of app security and operating system design. Even when application developers implement strong encryption—as Signal does—the underlying platform can inadvertently undermine those protections through caching, temporary files, or other system-level functions. Signal has long positioned itself as a privacy-first alternative to mainstream messaging apps. The platform has gained particular traction among activists, lawyers, and security professionals who require strong guarantees that their conversations cannot be intercepted or accessed by third parties. For typical Signal users, the patch requires updating to the latest iOS version. No evidence has emerged suggesting the vulnerability was exploited in the wild before being fixed.

■ SOURCES

Ars Technica

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Artificial intelligence is accelerating the rate at which security flaws are discovered, overwhelming traditional remediation systems designed for slower timelines. Organizations now face pressure to modernize their vulnerability management infrastructure.

JUST NOWAI Desk

Nicola Coughlan, Hugh Bonneville, and Matt Lucas are among approximately 80 signatories backing a campaign to ban AI voice cloning. The group has submitted an open letter to Manchester Mayor Andy Burnham demanding legal protections for voice ownership.

JUST NOWAI Desk

Brave browser version 1.94 now includes Email Aliases, a feature that generates disposable email addresses for new service signups. The tool helps users mask their primary email and reduce tracking across platforms.

JUST NOWAI Desk

The Department of Homeland Security is leveraging a little-known legal provision to request records from journalists, non-profits, and unions, according to reporting from The Guardian. The tactic raises concerns about surveillance overreach and First Amendment protections.

4H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.