iOS 26.6 Will Warn You About Malicious iMessages - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

iOS 26.6 Will Warn You About Malicious iMessages

Apple is adding a new warning about malicious iMessages in iOS 26.6, according to X user @limpless_skelly, who shared a mockup of the notification.

General Apps Messages Redux
The pop-up will warn users that a message could be trying to harm their iPhone or compromise their privacy. Apple asks users to share the message so it can guard against future attacks, and there are "Not Now," "Share With Apple," and "Don't Report" options to tap. Not Now likely causes the pop-up to surface again at a later time.


The actual alert hasn't been seen yet, but code in iOS 26.6 beta 5 confirms that it is indeed in the beta. It's not yet clear what messages will cause it to appear, but it could be a response to sophisticated exploits and phishing attempts in the Messages app. Apple added a "BlastDoor" sandbox security system to Messages in iOS 14, but in 2021, there was a zero-click iMessage exploit that was able to circumvent it and install spyware on the target device. Apple has since added Lockdown Mode and iMessage Contact Key Verification for extra security, along with spam message filtering.

Unfortunately, the alert looks similar to some of the fake scam pop-ups that show up in Safari, which could confuse iPhone users.

Apple has released five betas of iOS 26.6 so far, and it's nearing a public launch. We're expecting the update to come out sometime around the end of July.

Related Roundups: iOS 26, iPadOS 26
Related Forum: iOS 26

Popular Stories

iOS 26 6 2

Apple Releases iOS 26.6.2

Tuesday September 8, 2026 10:47 am PDT by
Apple today released iOS 26.6.2 with a fix for "an issue that prevents downloading a software update over a cellular connection." The minor software update is rolling out now for the iPhone 11 series and newer. To update your iPhone, open the Settings app and tap on General → Software Update. It might take a few minutes for the update to be visible to everyone. iOS 26.6.2 arrives...
ios 26 7

Apple Releases iOS 26.7 With Security Fixes

Monday September 14, 2026 10:32 am PDT by
Alongside iOS 27, Apple today released iOS 26.7, an update to the existing iOS 26 software. Users who check for new software will see iOS 26.7 as the default update, with iOS 27 listed as an option at the bottom of the Software Update interface. According to Apple's release notes, iOS 26.7 includes security fixes, but it does not have any other features. Apple will eventually show iOS 27 ...
apple lock security bug vulnerability fix privacy

iOS 27 and iOS 26.7 Fix More Than 100 Security Bugs

Monday September 14, 2026 11:36 am PDT by
Today's iOS 27 update addresses over 100 security vulnerabilities, which is a good reason to install the new software. If you don't want to update to iOS 27 yet, Apple also released iOS 26.7 with over 80 security fixes. 75 of the fixes are shared across both updates, so iOS 26.7 addresses many of the same issues. There are multiple kernel fixes, including one that could allow a malicious...

Top Rated Comments

9 weeks ago
It does look EXACTLY like those fake antivirus pop-ups that show up in Safari.
Maybe they should add a logo with a certified badge or something to display it comes from iOS or Apple.

I would like to know how it detects the message is malicious before it’s shared with Apple though. Heuristic analysis? Some Siri AI capability 🤔?
Score: 11 Votes (Like | Disagree)
jeroenvip Avatar
9 weeks ago
Feels like a band-aid. The verification tech already exists — email got SPF/DKIM/DMARC decades ago, voice got STIR/SHAKEN in 2018, and Apple itself shipped iMessage Contact Key Verification back in iOS 17. But it's opt-in, buried in settings, and basically nobody uses it. So instead of making sender verification the default, we get a popup that arrives after the malicious message does and asks you to report it. And as others said it looks exactly like the fake antivirus popups it's meant to protect people from.
Score: 5 Votes (Like | Disagree)
963852741 Avatar
9 weeks ago
My name is Giovanni Giorgio, but friends call me Giorgio.
Score: 5 Votes (Like | Disagree)
Andy_2341 Avatar
9 weeks ago
This is great but not well executed. We need a new design for these pop-ups Apple.
Score: 4 Votes (Like | Disagree)
9 weeks ago

What is needed to educate & encourage people to use contact key verification?
Well, Apple has no qualms about full screen takeovers to make sure you know about Lionel Messi or Genmoji or Apple Music. They make you go through about ten setup screens and coerce you into signing in to iCloud, all sorts of stuff.

They could reduce the ad-load and use those popups to help people rather than profit from them.

But when I type it out like that, doesn't sound like the kind of sentence executives want to hear.
Score: 3 Votes (Like | Disagree)
9 weeks ago

Feels like a band-aid. The verification tech already exists — email got SPF/DKIM/DMARC decades ago, voice got STIR/SHAKEN in 2018, and Apple itself shipped iMessage Contact Key Verification back in iOS 17. But it's opt-in, buried in settings, and basically nobody uses it. So instead of making sender verification the default, we get a popup that arrives after the malicious message does and asks you to report it. And as others said it looks exactly like the fake antivirus popups it's meant to protect people from.
What is needed to educate & encourage people to use contact key verification?
Score: 2 Votes (Like | Disagree)