
Encrypted RCS Makes Messaging Private Across Platforms, but Not Yet Universal
The new protection weakens an old privacy boundary between iPhone and Android while exposing how much standards still depend on apps and carriers.
For years, the safest everyday messaging usually required everyone in a conversation to choose the same app. An iPhone group could use iMessage. Android users could use encrypted RCS in Google Messages. Mixed groups often fell back to a less protected path or moved to a separate service such as Signal or WhatsApp.
That boundary has started to change. Apple and Google began rolling out end-to-end encrypted RCS between iPhone and Android in May. The feature is included in iOS 26.5 and the latest Google Messages, appears as a lock inside supported conversations, and is enabled by default when the necessary pieces are available.
The timing matters again because Samsung ended its own Messages app for most affected US customers in July and directed them to Google Messages. Two developments that look separate are converging. Cross-platform privacy is moving into a shared industry standard, while the number of major applications implementing that standard is becoming smaller.
RCS, or Rich Communication Services, is the mobile industry’s replacement for SMS and MMS. It supports features people now expect from modern chat, including high-quality media, typing indicators, read receipts and better group conversations.
The latest security work is part of the GSMA’s RCS Universal Profile 3.0. It uses the Messaging Layer Security protocol, an open technical standard designed to protect conversations involving two people or a changing group.
End-to-end encryption means the message content is encrypted on the sender’s device and can be decrypted only by devices in the conversation. Apple, Google, mobile carriers and an observer on the network should not be able to read that content while it is being delivered. The protocol also authenticates senders and updates the group’s cryptographic keys when membership changes.
This protection is different from ordinary transport encryption. Transport encryption can secure a message between a phone and a server, then expose it at the server before another protected connection begins. End-to-end encryption keeps the content protected through the intermediaries.
It does not make a conversation invulnerable. A compromised phone can reveal messages after decryption. A recipient can copy or photograph what appears on screen. Services may still retain operational information needed to route traffic, and backup protection depends on the device and account settings around the conversation. The lock is meaningful, but it is not a promise that every surrounding system has become private.
The important shift is not a new chat feature. It is that encryption can now follow the communication format rather than the brand of phone.
Private messaging apps proved that end-to-end encryption could work at global scale. Their weakness as a default is coordination. Before the protection helps, every participant must install the service, create an account and agree to use it. A standards-based approach can protect the ordinary conversation a person starts with a phone number, without asking the group to reorganize first.
That has particular value for mixed-device families, schools, neighborhood groups and small organizations. Many routine conversations do not justify a debate over which app to install. Improving the path people already use raises the baseline for everyone who would otherwise continue with SMS.
Standards also outlast individual product decisions. Apple, Google and carriers can change interfaces and business strategies while still supporting the same interoperable format. Other compliant clients could, in principle, join later without inventing another private network.
The rollout also shows the limit of that ideal. Encryption remains labeled as beta. It requires a recent Apple operating system, the latest Google Messages on Android, supported devices and participating carriers. Apple says availability will expand over time, which means an RCS conversation may be encrypted for one contact and not another.
Users therefore need to look for the lock rather than assume that every colorful chat bubble has the same protection. If the required support is missing, a conversation may use unencrypted RCS or fall back to SMS or MMS. The visual similarity between these paths can conceal a major security difference.
Samsung’s decision adds another complication. Moving customers to Google Messages improves consistency and gives more Android users the client involved in the encrypted rollout. It also removes a prominent alternative messaging app in the US. The protocol may be industry-wide, but Google now controls the main Android interface through which many people experience it.
This is a recurring pattern in technology. An open standard can reduce dependence on one platform while implementation consolidates around a few large vendors. Interoperability and market diversity are related, but they are not the same achievement.
Encrypted RCS will not replace dedicated private messengers. Signal still offers a more focused privacy model. Other services have broader international networks, richer communities or stronger control over backups and identity.
The value of RCS is more ordinary. It upgrades the least deliberate messages, the ones sent before anyone thinks about choosing a secure service. That is where standards often have their greatest effect. They turn a protection from an enthusiast’s preference into infrastructure that can disappear into daily use.
The rollout is incomplete, carrier-dependent and concentrated in two major apps. Those are real limitations. Still, a lock appearing in an iPhone-to-Android conversation marks a useful change in what people should expect. Private communication no longer has to stop at the edge of a device ecosystem. The next test is whether that expectation becomes reliable enough that users no longer need to inspect every thread to know which privacy rules apply.
