The most significant iPhone Android messaging update security change in years arrived quietly in May 2026: texts sent between iPhone and Android devices over RCS are now end-to-end encrypted by default, closing a gap that had left cross-platform messages readable in transit for as long as SMS and RCS have existed. The change began rolling out in beta with iOS 26.5, alongside a matching update to Google Messages on Android.
For most users, nothing about the process of sending a text changes. Encryption is enabled automatically over time for both new and existing RCS conversations, with no settings to toggle. The visible difference is a small lock icon that now appears in RCS chat threads once a conversation is confirmed to be end-to-end encrypted.
What Changed: Default End-to-End Encrypted RCS
The update is built on GSMA's RCS Universal Profile 3.0, using the Messaging Layer Security, or MLS, protocol to provide the encryption layer. When a conversation is end-to-end encrypted under this standard, the message content cannot be read while it travels between devices, whether by carriers, by Apple or Google's own servers, or by anyone intercepting the connection in between.
Both the sending and receiving device, along with the carriers involved, need to support Universal Profile 3.0 for encryption to activate on a given conversation. Major US carriers already support the standard, and Canada, along with several European carriers including O2, 1&1 and Telekom in Germany, are also on board, meaning coverage will vary by region and carrier for some time yet.
Key Details: What Encryption Does and Does Not Cover
It is worth being precise about the boundaries of this protection. Metadata, meaning who you texted, when, and how often, falls outside the encryption's scope. The update protects message content specifically, not the broader pattern of communication that metadata can reveal. Users looking for full metadata protection would still need a dedicated end-to-end encrypted messaging app rather than relying on RCS.
The lock icon appearing in a conversation is the clearest signal that encryption is active for that specific thread; conversations with contacts on unsupported carriers or older software will continue operating without it until both sides are upgraded.
Why It Matters
The timing and motivation behind this rollout trace back to a specific warning. The FBI told Americans in December 2024 to stop texting across platforms over unencrypted SMS and RCS, following confirmed nation-state attacks targeting exactly that unencrypted traffic. That warning highlighted a genuine, practical security gap: iPhone-to-Android texts had none of the encryption protections that iMessage-to-iMessage or many dedicated messaging apps already provided, even though most users had no way to know which of their conversations were protected and which were not.
Ending that gap matters because cross-platform texting is extremely common. Mixed iPhone and Android households, including the kind of cross-platform file and message sharing Samsung and Apple have separately been enabling, workplaces and friend groups routinely send sensitive information, from one-time passcodes to personal details, over RCS without realizing the message was traveling unencrypted the entire time it crossed between an iPhone and an Android device.
Industry Context: A Multi-Year Standoff Ends
Apple resisted adopting RCS for years, and public pressure over the "green bubble" divide between iPhone and Android messaging was as much about interoperability as security. When Apple finally added RCS support, encryption was not initially part of the deal, leaving the security gap the FBI later flagged. This May 2026 update, arriving roughly a year and a half after that FBI warning, represents the resolution of that standoff, achieved through the industry-standard GSMA Universal Profile rather than a proprietary Apple or Google-only encryption scheme.
Using an open standard matters because it means the fix does not depend on both parties using devices from the same company. Encryption applies across the iPhone and Android ecosystem as long as both devices and their carriers meet the Universal Profile 3.0 requirement.
What It Means for Users
Practically, users do not need to do anything beyond keeping their devices updated to iOS 26.5 or later, and the equivalent Google Messages update on Android, to benefit from this change. Checking for the lock icon in a given conversation is the simplest way to confirm whether a specific thread is currently protected.
Users communicating with contacts on carriers that have not yet adopted Universal Profile 3.0, or with contacts running older software, should be aware that those specific conversations will not show the lock icon and remain unencrypted until both sides update.
How This Compares to iMessage's Existing Encryption
Apple's own iMessage service has offered end-to-end encryption between iPhones for years, which is part of why the RCS gap stood out as such a glaring inconsistency: two iPhone users texting each other were fully protected, while an iPhone user texting an Android contact was not, even though both conversations looked identical on screen, aside from bubble color. The May 2026 update does not merge RCS encryption into iMessage's own protocol; it brings RCS up to a comparable standard of protection using the separate, carrier-and-industry-backed Universal Profile 3.0 and MLS combination instead. The practical result for users is similar, encrypted-by-default messaging, but the technical implementation and the standards body behind it are different, and that distinction matters for how quickly other manufacturers and carriers worldwide can adopt the same protection.
What Security Researchers Are Saying
Security researchers have generally welcomed the change while cautioning against overstating what it fixes. Encrypting message content closes a specific, well-documented gap that the FBI itself had flagged as actively exploited by nation-state actors, which is a genuine, meaningful improvement. But researchers are quick to note that metadata protection, disappearing carrier-level support gaps, and the broader question of device-level security, including issues like the notification-cache vulnerability that separately allowed forensic recovery of deleted messages on iOS, remain areas where cross-platform messaging security still has real limitations beyond what this specific update addresses.
What Happens Next
Expect broader carrier adoption of Universal Profile 3.0 to continue through the rest of 2026 as more regions and carriers roll out support. Full global coverage will likely take time, following the same uneven, carrier-by-carrier rollout pattern that has characterized RCS adoption more broadly since Apple first added support for the standard.
Final Takeaway
The iPhone Android messaging update security rollout that began in May 2026 closes a long-standing, well-documented encryption gap between the two largest mobile platforms, using an open industry standard rather than a proprietary fix. It does not protect metadata, and coverage still depends on carrier support, but for message content itself, cross-platform texting is now meaningfully more secure than it was a year ago.
FAQs
- iOS 26.5, released in May 2026, brings default end-to-end encrypted RCS messaging between iPhone and Android using GSMA's Universal Profile 3.0 and the MLS protocol.
- The update follows a December 2024 FBI warning about nation-state attacks on unencrypted cross-platform texts.
- Encryption covers message content but not metadata, and requires both devices and carriers to support the new standard.
Sources and Verification
- 9to5Google, Encrypted RCS rolling out with iOS 26.5
- The Hacker News, iOS 26.5 default end-to-end encrypted RCS
This article was reviewed as part of CapisTech's editorial fact-checking process.
