Pavel Durov Warns Push Notifications Have Become a Privacy Attack Surface
Messaging services such as Signal use end-to-end encryption to protect messages, but an iPhone may separately retain content and metadata in its notification database to display push previews. Device forensics may therefore recover records even after messages have been set to disappear or the app has been deleted. The case shows that privacy risks extend beyond messaging protocols to the system layers of platforms such as Apple.
On April 11, 2026, Telegram founder Pavel Durov cited a US Federal Bureau of Investigation case disclosed by 404 Media in which investigators extracted a Signal user's deleted messages from iPhone push-notification records. He also advocated decentralized messaging tools that do not collect metadata. Apple released iOS 26.4.2 and iOS 18.7.8 on April 22, fixing CVE-2026-28950.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →