· Added

Apple fixed a bug where deleted notifications could be retained on-device (iOS 26.4.2)

A credited summary of Apple’s April 22, 2026 security note for iOS 26.4.2: notifications marked for deletion could be unexpectedly retained on the device. Practical takeaway for app teams: treat notifications as a privacy and trust surface, and keep lock screen content minimal.


Original post (source): Apple Support - “About the security content of iOS 26.4.2 and iPadOS 26.4.2” (Apr 22, 2026)


Summary

Apple’s iOS 26.4.2 and iPadOS 26.4.2 security note includes a fix for a notification privacy issue:

  • Impact (Apple’s wording): notifications marked for deletion could be unexpectedly retained on the device.
  • Fix: Apple says a logging issue was addressed with improved data redaction.
  • Reference: CVE-2026-28950.

Apple does not provide a lot of operational detail (as expected for security notes), but the practical interpretation is straightforward: notifications can be more persistent than teams assume, and the lock screen plus notification history should be treated as a sensitive surface.

Why this matters

If your app sends notifications that include:

  • personal data,
  • health or finance details,
  • one-time codes,
  • or “sensitive by context” information,

then “preview content” is not just a UX decision. It is a trust and risk decision.

This also matters for retention and CRM teams: notification copy and preview behavior can affect opt-outs, complaints, and support load.

What to do next (tiny win)

Pick your most-triggered notification and apply a safe-default rule:

  • make the lock screen preview generic (no personal details), and
  • deep link to the detail screen inside the app after unlock.

If you have any notification types that truly must include sensitive content, add an in-app setting for preview level (full preview vs generic), and default it to the safer option.


Read the original: https://support.apple.com/en-us/127002

Editor: App Store Marketing Editorial Team

Insights informed by practitioner experience and data from ConsultMyApp and APPlyzer.

Want help with ASO?

If you want this implemented for your app, check out our services - or run your workflow in APPlyzer.