苹果修复了一个漏洞,警察曾利用该漏洞从iPhone中提取已删除的聊天信息。
Apple fixes bug that cops used to extract deleted chat messages from iPhones

原始链接: https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/

苹果公司最近发布了一项软件更新,以解决一个安全漏洞,该漏洞允许执法部门访问iPhone和iPad上已删除的消息。此漏洞源于缓存的通知——即使在Signal等应用程序中删除了消息,通知内容仍可能在设备上存储长达一个月。 该问题浮出水面,源于报告显示FBI使用法医工具成功提取了已删除的Signal消息。Signal敦促苹果修复此问题,强调已删除的通知不应保留在操作系统数据库中。 尽管记录原因尚不清楚,苹果公司现已修复了当前和旧版iOS中的此漏洞。这项修复对于依赖消失消息功能以保护隐私的用户至关重要,因为它恢复了预期的安全保障,即使设备被当局查封,也能防止数据恢复。苹果公司尚未对此漏洞存在的原因发表评论。

## 苹果修复iPhone聊天信息提取漏洞 苹果最近修补了一个漏洞,该漏洞允许执法部门从iPhone中提取已删除的聊天信息。问题源于本地缓存的通知数据——即使删除了Signal等应用程序,消息预览仍然可以从手机的系统日志中访问。苹果的修复确保已删除的应用程序通知也会从这些日志中删除。 然而,此次讨论凸显了更广泛的隐私问题。专家指出,苹果和谷歌对通知的控制意味着消息内容会经过它们的服务器,可能存在被监控的风险。虽然端到端加密存在,但通知预览本身可以绕过这种安全措施。 建议用户在iOS设置中禁用消息预览(“永不显示预览”)或使用Signal等提供通用通知选项的应用程序(“您收到了一条消息”)。核心问题不仅仅是这个漏洞,而是操作系统在安全消息应用程序之外存储通知文本。此修复解决了特定实例,但并未解决操作系统层面数据保留的根本问题。
相关文章

原文

Apple released a software update on Wednesday for iPhones and iPads fixing a bug that allowed law enforcement to extract messages that had been deleted or disappeared automatically from messaging apps. This was because notifications that displayed the messages’ content were also cached on the device for up to a month.

In a security notice on its website, Apple said that the bug meant “notifications marked for deletion could be unexpectedly retained on the device.”

This is a clear reference to an issue revealed by 404 Media earlier this month. The independent news outlet reported that the FBI had been able to extract deleted Signal messages from someone’s iPhone using forensic tools, due to the fact that the content of the messages had been displayed in a notification and then stored inside a phone’s database — even after the messages were deleted inside Signal.

After the news, Signal president Meredith Whittaker said the messaging app maker asked Apple to address the issue. “Notifications for deleted messages shouldn’t remain in any OS notification database,” Whittaker wrote in a post on Bluesky.

Contact Us

Do you have more information about how authorities are using forensic tools on iPhones or Android devices? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

It’s unclear why the notifications’ content was logged to begin with, but today’s fix suggests it was a bug. 

Apple did not immediately respond to a request for comment asking why the notifications were being retained. The company also backported the fix to iPhone and iPad owners running the older iOS 18 software.

Privacy activists expressed alarm when they learned that the FBI had found a way around a security feature that is used daily by at-risk users. Signal, like other messaging apps such as WhatsApp, allows users to set up a timer that instructs the app to automatically delete messages after a set amount of time. This feature can be helpful for anyone who wants to keep their conversations secret in the event that authorities seize their devices.

Techcrunch event

San Francisco, CA | October 13-15, 2026

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

联系我们 contact @ memedata.com