Apple fixes bug that cops used to extract deleted chat messages from iPhones

Apple patched a critical security vulnerability that allowed law enforcement to extract deleted messages from iPhones by accessing cached notification data retained for up to a month, exposing a significant gap between user expectations of message deletion and actual data persistence. This incident highlights the risk that security features relied upon by at-risk populations can be circumvented through OS-level vulnerabilities, creating both legal and reputational exposure for organizations managing sensitive communications. IT leaders must reassess how notification systems and data retention policies across their infrastructure may unintentionally preserve sensitive information despite user-initiated deletion.

Hacker News3 min read
Read full article
Apple fixes bug that cops used to extract deleted chat messages from iPhones
Apple patched a critical security vulnerability that allowed law enforcement to extract deleted messages from iPhones by accessing cached notification data retained for up to a month, exposing a significant gap between user expectations of message deletion and actual data persistence. This incident highlights the risk that security features relied upon by at-risk populations can be circumvented through OS-level vulnerabilities, creating both legal and reputational exposure for organizations managing sensitive communications. IT leaders must reassess how notification systems and data retention policies across their infrastructure may unintentionally preserve sensitive information despite user-initiated deletion.