AIO APEX

iPhone and Android text messages are finally getting real end-to-end encryption between platforms

Share:
iPhone and Android text messages are finally getting real end-to-end encryption between platforms

For the first time, a text message sent from an iPhone to an Android phone can be end-to-end encrypted by default, using an open industry standard rather than a proprietary app. As of May 2026, the GSMA's standard for end-to-end encryption (E2EE) over Rich Communication Services (RCS) is in active rollout across both Google Messages and Apple Messages — the default texting apps on the two platforms that carry the overwhelming majority of the world's mobile messages.


This closes a gap that has been sitting in plain sight since Apple added RCS support to Messages with iOS 18 in September 2024. RCS itself replaced the old SMS/MMS protocol with modern features — read receipts, typing indicators, high-resolution media, better group chats — but cross-platform encryption wasn't part of the original rollout. Google Messages had offered E2EE for Android-to-Android RCS chats since 2022, but a message crossing from an iPhone to an Android device, or vice versa, traveled without end-to-end protection until this standard closed that hole.


How the standard actually works

The GSMA added E2EE to the RCS Universal Profile in March 2025 using Messaging Layer Security (MLS), an IETF-standardized protocol originally designed for scalable encrypted group messaging. MLS was a deliberate choice: unlike the Signal Protocol that iMessage and WhatsApp use internally, MLS is built to let independent implementations from different vendors interoperate securely, which is exactly the problem RCS across Apple and Google needed to solve. Apple and Google each maintain separate RCS clients — Messages on iOS and Google Messages on Android — and neither company was going to hand its messaging security implementation to the other. MLS lets both build to the same open specification and still achieve verified end-to-end encryption between them.

Practically, this means a chat between an iPhone user and an Android user now gets the same core guarantee iMessage-to-iMessage or WhatsApp-to-WhatsApp users have had for years: the network operator, the phone manufacturer, and the messaging provider itself cannot read the message content in transit. Only the sender and recipient devices hold the keys.


Why this took until 2026

The technical delay traces back to a genuine standards problem, not corporate foot-dragging alone. RCS launched in 2008 and spent its first decade fragmented across carrier-specific implementations with no common feature set, which is why the GSMA had to define the Universal Profile in 2016 just to get baseline interoperability working. Encryption is a harder problem than read receipts: it requires key exchange and identity verification protocols that must survive adversarial conditions, work across carrier networks with wildly different infrastructure maturity, and not break when a user switches phones, SIM cards, or carriers. Google shipped E2EE for its own Android-to-Android implementation years before the cross-platform standard existed, precisely because solving it for one company's client is a fundamentally smaller problem than getting two competing platform makers to interoperate securely.

Apple's decision to support RCS at all in 2024 was itself notable — Apple had resisted RCS for years, partly under regulatory pressure related to messaging interoperability requirements in markets like the EU. Once Apple committed to RCS, closing the encryption gap became a matter of when, not if, but building a cross-vendor encryption standard that both companies would actually trust and ship took roughly 18 months after Apple's initial RCS launch.


What to actually check on your phone

E2EE is rolling out, not universally live yet, so a few things determine whether any given conversation is protected:

  • Both parties need RCS enabled — if either side has RCS turned off, or one phone falls back to SMS due to poor signal, the conversation reverts to unencrypted SMS/MMS with none of RCS's protections.
  • Carrier support varies — some carriers still route RCS through Google's Jibe backend rather than providing it natively, and Google has been discontinuing that fallback service since 2025, meaning users on carriers without direct RCS support may lose functionality during the transition rather than gain it.
  • Desktop clients need to catch up — RCS is also accessible via Google Messages' web client and Microsoft Phone Link, and encryption support across those secondary access points is not guaranteed to match the mobile rollout timeline.

For most users, the practical takeaway is to check for a lock icon or encrypted label in a conversation thread on Messages or Google Messages; its presence confirms the standard is active for that specific chat, not just theoretically available on the network.


The bigger picture

RCS now claims an estimated 2.5 billion monthly active users worldwide, and closing the encryption gap between the two dominant mobile ecosystems removes one of the last major arguments for sticking with third-party encrypted messengers purely for cross-platform security. It doesn't eliminate the case for apps like Signal or WhatsApp — those offer additional features and, in Signal's case, a stronger metadata-privacy model — but it does mean the default texting experience for the average user crossing between iPhone and Android is no longer a security downgrade by default. That is a meaningful, if quiet, upgrade to baseline privacy for thousands of everyday conversations.

Share:
RCS End-to-End Encryption Now Live Between iPhone and Android | AIO APEX