What changed (October 3, 2026): Apple closed the underlying retention flaw on April 22, 2026 with iOS/iPadOS 26.4.2 and iOS/iPadOS 18.7.8 (CVE-2026-28950). Signal confirmed on X that "no action is needed for this fix to protect Signal users on iOS." On February 11, 2026, a federal jury convicted the four Prairieland defendants, including Lynette Sharp, after a trial in which the FBI's extraction of her deleted Signal messages from the iPhone notification database was entered into evidence. The "Fix it in 15 seconds" advice below is still correct for users who cannot or have not yet installed the patch.
TL;DR:
- FBI agents extracted deleted Signal messages from a defendant's iPhone, even after Signal was completely uninstalled, by pulling them from Apple's push notification database.
- The technique was revealed during testimony by FBI Special Agent Clark Wiethorn in a federal terrorism case tied to a July attack on an ICE detention facility in Texas.
- This isn't a Signal flaw. Any messaging app that shows message content in notifications leaves traces in iOS storage that survive app deletion.
- Only incoming messages were recovered. Outgoing messages don't pass through the push notification system.
- Fix it in 15 seconds: Open Signal → Settings → Notifications → Notification Content → select "No Name or Message." This prevents iOS from storing readable message text.
What Happened in Court
In April 2026, FBI Special Agent Clark Wiethorn took the stand in a federal terrorism trial and described something that should worry every Signal user.
Defendant Lynette Sharp had pleaded guilty to providing material support to terrorists in connection with a July attack on the ICE Prairieland Detention Facility in Alvarado, Texas. The group allegedly set off fireworks, vandalized property, and one member allegedly shot a police officer in the neck. It was the first case where authorities charged defendants for alleged "Antifa" activities following President Trump's designation of the umbrella term as a terrorist organization.
Sharp had deleted Signal from her iPhone. She probably thought that destroyed the evidence.
It didn't. The FBI used forensic extraction tools to pull copies of her incoming Signal messages from a database she didn't know existed: Apple's push notification storage system.
As 404 Media's Joseph Cox first reported, the messages were sitting in the iPhone's BulletinBoard framework, the system iOS uses to manage notifications, completely independent of the Signal app itself.
How Your Phone Betrays Your "Encrypted" Messages
Here's the pipeline that turns end-to-end encryption into a forensic evidence trail:
- Signal receives an incoming message. The message arrives encrypted and gets decrypted on your device. So far, so good.
- Signal generates a notification. If you have message previews enabled (the default), Signal hands the decrypted message content to iOS to display on your lock screen.
- iOS stores the notification. Apple's BulletinBoard framework, located at
/private/var/mobile/Library/BulletinBoard/, caches notification data including the full message text, timestamps, and the sending app's identifier. - You delete Signal. The app is gone. But the notification database entries? They stay. iOS doesn't purge notification records when an app is uninstalled.
- Law enforcement seizes your phone. Using commercial forensic tools like Cellebrite UFED or Magnet AXIOM, they extract the notification database and read your "deleted" messages.
The critical detail: this only captures incoming messages. Outgoing messages you sent don't generate push notifications on your own device, so they bypass this storage entirely.
But incoming messages, the ones other people sent you, survive in a database most iPhone users have never heard of.
This Isn't a Signal Bug. It's an iOS Problem.
Signal's encryption works exactly as designed. Messages are encrypted in transit and decrypted only on the recipient's device. The protocol is solid.
The problem is what happens after decryption. Once iOS gets the notification text, it's Apple's system managing that data, and Apple's system that retains it.
This means every messaging app with content previews is affected. WhatsApp, Telegram, iMessage, even email apps. If a notification shows you message content on your lock screen, iOS is caching that content in a forensically recoverable database.
Security researcher Andrea Fortuna broke down the technical details: the notification database's accessibility depends on the device's encryption state. After you enter your passcode the first time (moving from "Before First Unlock" to "After First Unlock" state), the notification data becomes accessible to forensic tools. Since most seized phones are in AFU state, your phone's been unlocked at least once since the last reboot, the data is typically there for the taking.
The mutable-content: 1 flag that Signal uses to decrypt message content via its Notification Service Extension is the exact mechanism that creates these forensic artifacts. The app decrypts the message, formats it for display, and iOS faithfully records the result.
The $15,000 Gadgets Reading Your Notifications
Law enforcement doesn't need to hack Signal's encryption. They just need physical access to your phone and one of several commercially available forensic tools:
- Cellebrite UFED, Used by over 5,000 law enforcement agencies worldwide. Can perform "advanced logical acquisition" that extracts system databases including notification storage.
- Magnet AXIOM, Parses iOS backup protocols and system-level data stores. Specifically designed to recover artifacts that survive app deletion.
- GrayKey (Grayshift), Can bypass iPhone passcodes in some configurations, giving full filesystem access including notification databases.
These aren't theoretical capabilities. Agent Wiethorn testified about using them in a federal courtroom. This is standard practice.
The tools exploit a fundamental gap: Signal protects messages in transit. Apple protects data on disk with filesystem encryption. But between those two protections, in the moment iOS receives notification content and writes it to a database, there's a window. And that window stays open permanently, because iOS doesn't clean up after deleted apps.
Push Notifications: The Surveillance Backdoor Nobody Talks About
This isn't the first time push notifications have created a privacy problem. In December 2023, Senator Ron Wyden revealed that the U.S. government had been secretly demanding push notification records from Apple and Google. Those requests captured metadata, which app sent the notification, when, to what device, flowing through Apple and Google's servers.
This new technique is different and arguably worse. The FBI isn't requesting metadata from Apple's servers. They're recovering decrypted message content from your physical device. Content that end-to-end encryption was specifically designed to protect.
The architecture of push notifications creates two separate surveillance vectors:
- Server-side: Apple and Google see notification metadata (and sometimes content) when it transits their Push Notification Service infrastructure. Governments can subpoena this.
- Device-side: iOS caches notification content locally in a database that survives app deletion. Law enforcement can extract this with physical access and forensic tools.
Encrypted messaging promised one thing: only you and the recipient can read your messages. Push notifications quietly broke that promise from day one.
Fix This Right Now
The good news: you can shut this down. The bad news: it's not the default setting.
Signal (do this first)
- Open Signal
- Tap your profile icon (top left)
- Tap Notifications
- Tap Notification Content
- Select "No Name or Message"
This tells Signal to send a generic "New Message" notification instead of the actual text. iOS caches "New Message", useless to forensic tools.
- Settings → Notifications
- Disable "Show Preview" for both Message and Group notifications
Telegram
- Settings → Notifications and Sounds
- Disable "Message Preview" under each notification category
iOS system-wide (belt and suspenders)
- Settings → Notifications
- Tap "Show Previews"
- Select "Never" or "When Unlocked"
"When Unlocked" is the minimum, it prevents content from being cached while the phone is in BFU state. "Never" is safer. You'll still get notification alerts; they just won't contain readable message text.
Already compromised?
If you've been running Signal with default notification settings, your notification database already contains cached message content. Changing the setting only prevents future messages from being stored. Old artifacts persist until they're overwritten by the system, which iOS does eventually, but there's no way to force it.
For high-risk individuals: a full device wipe and restore (not from backup, which may include the notification database) is the nuclear option. Most people don't need to go that far. Just change the setting and move forward.
Update (October 3, 2026)
Two developments since the original article clarify how the case ended and what the underlying iOS flaw was. First, on February 11, 2026, a federal jury in Utah convicted Lynette Sharp and three co-defendants of providing material support to terrorists and other charges in the Prairieland case, sharply rejecting the defendants' self-defense claim. The trial is the one in which FBI Special Agent Clark Wiethorn testified about extracting Sharp's incoming Signal messages from the iPhone notification database; the evidence formed part of the record the jury weighed.
Second, on April 22, 2026, Apple released iOS/iPadOS 26.4.2 and iOS/iPadOS 18.7.8, which patch CVE-2026-28950, the underlying notification retention flaw. The vulnerability, per Apple's security advisory, was a logging issue in Notification Services in which notifications marked for deletion were unexpectedly retained on the device. Apple classified the fix as "improved data redaction." Signal confirmed on X that "no action is needed for this fix to protect Signal users on iOS." Backports were also published for older iOS versions (15.8.8 and 16.7.16).
For users on a patched iOS, the iOS layer above no longer caches readable message text in the notification database. The Signal-in-Settings mitigation at the bottom of this article still matters for anyone who has not installed 26.4.2 or 18.7.8, and as a defense-in-depth measure for users who cannot patch. The technique the FBI used in 2026 still works against any iPhone that has not been updated, and the precedent the Prairieland conviction sets, that messages pulled from the notification database are admissible, remains in place.
Sources for this update: The Hacker News. "Apple Fixes iOS Flaw That Stored Deleted Signal Messages for the FBI." April 23, 2026; SANS Internet Storm Center. "Apple Patches Exploited Notification Flaw." April 23, 2026; Help Net Security. "Apple fixes iPhone bug that let FBI retrieve deleted Signal messages." April 23, 2026; Utah News Dispatch. "Utah Antifa members convicted in federal trial, sharply rejecting self-defense claim." February 11, 2026.
Sources
- 404 Media: "FBI Extracts Suspect's Deleted Signal Messages Saved in iPhone Notification Database"
- 9to5Mac: "FBI used iPhone notification data to retrieve deleted Signal messages"
- Cyber Insider: "FBI retrieved deleted Signal messages from iPhone notification database"
- Andrea Fortuna: "When deleting Signal is not enough: the FBI, iPhone notifications, and what forensics can reveal"
- CDM: "FBI Recovers Deleted Signal Messages From Suspect's iPhone Via Notification Database In Texas Terrorism Case"
- Senator Wyden: "Wyden Reveals U.S. Government Surveillance of Push Notifications" (December 2023)
Published: April 13, 2026. Updated: October 3, 2026.