2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

iOS 26.5 Introduces Default End-to-End Encrypted RCS Between iPhone and Android


Apple rolled out iOS 26.5 on Monday, bringing beta support for end-to-end encryption (E2EE) of Rich Communication Services (RCS) as part of a coordinated industry push to move users away from legacy SMS toward a more secure messaging standard.

The encrypted RCS functionality is becoming available to iPhone owners running iOS 26.5 who are on participating carriers, and to Android users who have the most recent version of Google Messages. Apple says the capability is switched on by default for both newly started and existing RCS conversations across the two platforms.

RCS is an IP-based messaging standard that provides features commonly found in modern messaging apps: high-resolution photo and video transfer, typing indicators, and read receipts. The protocol is implemented according to the RCS Universal Profile specification. When RCS conversations are protected with E2EE, Apple explained, the messages are unreadable while they travel between devices, and users will see a lock icon in conversations to indicate that encryption is active.

Apple first trialed E2EE for RCS in the iOS and iPadOS 26.4 beta releases, initially restricting it to chats between Apple devices. In early 2025, the GSM Association (GSMA) publicly backed E2EE for RCS as a means of protecting messages sent using the protocol.

Google has likewise confirmed that Google Messages will show a padlock emblem to signal when a cross-platform thread is secured with end-to-end encryption.

Alex Sinclair, chief technology officer at the GSMA, credited the progress to close cooperation across the mobile ecosystem, including Apple and Google, and emphasized that the encrypted services are being delivered on an open, internationally recognised standard.

Alongside the messaging enhancement, iOS and iPadOS 26.5 include fixes for more than 50 security flaws. The corrections address vulnerabilities across components such as AppleJPEG, ImageIO, the Kernel, mDNSResponder, and WebKit. According to Apple, these issues could have allowed information disclosure, denial-of-service conditions, or unexpected app or system termination if exploited.

The update represents a notable step in mobile messaging security by enabling encrypted RCS by default while also closing multiple potential attack vectors in Apple’s mobile operating systems.

First published on May 13, 2026.
Last updated on May 19, 2026.