iOS 26.6 Will Warn You About Malicious iMessages - MacRumors
Skip to Content

iOS 26.6 Will Warn You About Malicious iMessages

Apple is adding a new warning about malicious iMessages in iOS 26.6, according to X user @limpless_skelly, who shared a mockup of the notification.

General Apps Messages Redux
The pop-up will warn users that a message could be trying to harm their iPhone or compromise their privacy. Apple asks users to share the message so it can guard against future attacks, and there are "Not Now," "Share With Apple," and "Don't Report" options to tap. Not Now likely causes the pop-up to surface again at a later time.


The actual alert hasn't been seen yet, but code in iOS 26.6 beta 5 confirms that it is indeed in the beta. It's not yet clear what messages will cause it to appear, but it could be a response to sophisticated exploits and phishing attempts in the Messages app. Apple added a "BlastDoor" sandbox security system to Messages in iOS 14, but in 2021, there was a zero-click iMessage exploit that was able to circumvent it and install spyware on the target device. Apple has since added Lockdown Mode and iMessage Contact Key Verification for extra security, along with spam message filtering.

Unfortunately, the alert looks similar to some of the fake scam pop-ups that show up in Safari, which could confuse iPhone users.

Apple has released five betas of iOS 26.6 so far, and it's nearing a public launch. We're expecting the update to come out sometime around the end of July.

Related Roundups: iOS 26, iPadOS 26
Related Forum: iOS 26

Popular Stories

iOS 26

Apple Seeds iOS 26.6 and iPadOS 26.6 Release Candidates

Monday July 20, 2026 10:05 am PDT by
Apple today seeded the release candidate versions of upcoming iOS 26.6 and iPadOS 26.6 updates to developers for testing purposes, with the software coming a week after Apple seeded the fifth betas. The RCs represent the final version of the software that will be released soon should no additional bugs be found. Registered developers can download the betas from the Settings app on the...
iOS 26

Apple Releases iOS 26.6 and iPadOS 26.6 With iOS 27 Optimizations

Monday July 27, 2026 10:27 am PDT by
Apple today released iOS 26.6 and iPadOS 26.6, updates to the iOS and iPadOS 26 operating systems that came out in September. iOS 26.6 comes a month after the launch of iOS 26.5.2, a security update. iOS 26.6 and iPadOS 26.6 can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. According to Apple's release notes, iOS 26.6 and iPadOS ...
apple lock security bug vulnerability fix privacy

Update Now: iOS 26.6 and macOS Tahoe 26.6 Patch Hundreds of Security Flaws

Monday July 27, 2026 11:55 am PDT by
Apple today released iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6, all of which have a long list of security fixes. iOS 26.6 and iPadOS 26.6 address almost 90 security vulnerabilities affecting everything from the App Store to the Neural Engine. Multiple kernel and WebKit vulnerabilities were fixed, along with problems affecting Wi-Fi, Siri, and the iPhone's image processing. Details on...

Top Rated Comments

5 weeks ago
It does look EXACTLY like those fake antivirus pop-ups that show up in Safari.
Maybe they should add a logo with a certified badge or something to display it comes from iOS or Apple.

I would like to know how it detects the message is malicious before it’s shared with Apple though. Heuristic analysis? Some Siri AI capability 🤔?
Score: 11 Votes (Like | Disagree)
jeroenvip Avatar
5 weeks ago
Feels like a band-aid. The verification tech already exists — email got SPF/DKIM/DMARC decades ago, voice got STIR/SHAKEN in 2018, and Apple itself shipped iMessage Contact Key Verification back in iOS 17. But it's opt-in, buried in settings, and basically nobody uses it. So instead of making sender verification the default, we get a popup that arrives after the malicious message does and asks you to report it. And as others said it looks exactly like the fake antivirus popups it's meant to protect people from.
Score: 5 Votes (Like | Disagree)
963852741 Avatar
5 weeks ago
My name is Giovanni Giorgio, but friends call me Giorgio.
Score: 5 Votes (Like | Disagree)
Andy_2341 Avatar
5 weeks ago
This is great but not well executed. We need a new design for these pop-ups Apple.
Score: 4 Votes (Like | Disagree)
5 weeks ago

What is needed to educate & encourage people to use contact key verification?
Well, Apple has no qualms about full screen takeovers to make sure you know about Lionel Messi or Genmoji or Apple Music. They make you go through about ten setup screens and coerce you into signing in to iCloud, all sorts of stuff.

They could reduce the ad-load and use those popups to help people rather than profit from them.

But when I type it out like that, doesn't sound like the kind of sentence executives want to hear.
Score: 3 Votes (Like | Disagree)
5 weeks ago

Feels like a band-aid. The verification tech already exists — email got SPF/DKIM/DMARC decades ago, voice got STIR/SHAKEN in 2018, and Apple itself shipped iMessage Contact Key Verification back in iOS 17. But it's opt-in, buried in settings, and basically nobody uses it. So instead of making sender verification the default, we get a popup that arrives after the malicious message does and asks you to report it. And as others said it looks exactly like the fake antivirus popups it's meant to protect people from.
What is needed to educate & encourage people to use contact key verification?
Score: 2 Votes (Like | Disagree)