{"id":78993,"date":"2015-02-25T00:34:09","date_gmt":"2015-02-24T22:34:09","guid":{"rendered":"http:\/\/onsoftware.en.softonic.com\/?p=78993"},"modified":"2025-07-02T00:17:36","modified_gmt":"2025-07-02T07:17:36","slug":"most-vulnerable-operating-systems-study","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/most-vulnerable-operating-systems-study\/","title":{"rendered":"Windows more secure than OSX? Not so fast."},"content":{"rendered":"<p>A report published by <a title=\"GFI Software\" href=\"http:\/\/www.gfi.com\/blog\/most-vulnerable-operating-systems-and-applications-in-2014\/\" target=\"_blank\" rel=\"noopener noreferrer\">GFI Software<\/a>, a security software developer, revealed which operating systems have the most vulnerabilities. Shockingly, Apple\u2019s OS X and iOS topped the list of the least secure operating systems with Windows handily beating them. But are OS X and iOS really more vulnerable than Windows?<\/p>\n<p>Let\u2019s dive into the data.<\/p>\n<h3>What the report says<\/h3>\n<p>The study is based on data from the <a title=\"National Vulnerability Database\" href=\"http:\/\/nvd.nist.gov\/\" target=\"_blank\" rel=\"noopener noreferrer\">National Vulnerability Database<\/a> (NVD), which is a government run repository for security compliance and vulnerability data. GFI used data from the NVD reports and compiled some interesting data. Here\u2019s what we learned from GFI\u2019s report:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-78999\" title=\"GFI report OS chart\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2015\/02\/OS-chart-568x293.jpg\" alt=\"GFI report OS chart\" width=\"568\" height=\"293\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/OS-chart-568x293.jpg 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/OS-chart-256x132.jpg 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/OS-chart.jpg 813w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>&#8211; There is a steady increase in the number of vulnerabilities spotted year over year. Between 2013 and 2014, the number of vulnerabilities increased by 2,244, a <strong>47% increase<\/strong> in just one year.<\/p>\n<p>&#8211; Third party apps account for over 80% of the reported vulnerabilities. This is significant as the study doesn\u2019t point to the inherent security risks inside an operating system. <strong>Only 13% of vulnerabilities were attributed to the OS<\/strong>.<\/p>\n<p>&#8211; OS X and iOS both topped the charts with the most vulnerabilities and the most vulnerabilities labeled as <strong>high risk<\/strong>.<\/p>\n<p>&#8211; Linux is more vulnerable than Windows. GFI cites recent security issues like <a title=\"Heartbleed: the bug that left the internet vulnerable\" href=\"http:\/\/features.en.softonic.com\/heartbleed-everything-you-need-to-know\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed<\/a> for this outcome.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-79000\" title=\"GFI Application Chart\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2015\/02\/GFI-Application-Chart-568x330.jpg\" alt=\"GFI Application Chart\" width=\"568\" height=\"330\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/GFI-Application-Chart-568x330.jpg 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/GFI-Application-Chart-256x148.jpg 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/GFI-Application-Chart.jpg 811w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>&#8211; Microsoft\u2019s <strong>Internet Explorer is the lease secure browser<\/strong>, followed by Chrome and Firefox.<\/p>\n<h3>An incomplete picture<\/h3>\n<p>While these figures are shocking, it paints an incomplete picture of the current security landscape. \u201cBasically it\u2019s like staring at a bunch of garden walls to see how many footballs come flying over the top \u2013 it doesn&#8217;t say much about the height or quality of a given wall, but maybe something about how many people are on the other side and what kind of games they\u2019re playing,\u201d <a title=\"Virus Bulletin\" href=\"https:\/\/www.virusbtn.com\/index\" target=\"_blank\" rel=\"noopener noreferrer\">Virus Bulletin<\/a> Chief of Operations John Hawes.<\/p>\n<p style=\"text-align: center\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-78995\" title=\"footballs wall post\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-568x319.png\" alt=\"footballs wall post\" width=\"568\" height=\"319\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-568x319.png 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-256x144.png 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-800x450.png 800w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-664x374.png 664w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-300x169.png 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-238x134.png 238w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-768x433.png 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-436x246.png 436w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-370x208.png 370w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post-304x170.png 304w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/footballs-wall-post.png 1280w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><em>Image credit: <a title=\"Christopher Park Twitter\" href=\"https:\/\/twitter.com\/chrislikesrobot\" target=\"_blank\" rel=\"noopener noreferrer\">Christopher Park<\/a><\/em><\/p>\n<p>It\u2019s tempting to simply agree with GFI&#8217;s findings as Apple just had a <a title=\"Forbes\" href=\"http:\/\/www.forbes.com\/sites\/niallmccarthy\/2015\/01\/28\/apples-record-breaking-quarter-in-context-infographic\/\" target=\"_blank\" rel=\"noopener noreferrer\">record breaking quarter<\/a> selling <strong>74.5 million iPhones<\/strong>, making the iPhone a prime target for attackers. Studies show that iPhone users are also <a title=\"Cite World\" href=\"http:\/\/www.citeworld.com\/article\/2115335\/mobile-byod\/mirror-mirror-wall-which-most-lucrative-mobile-os-them-all.html\" target=\"_blank\" rel=\"noopener noreferrer\">more likely to pay for apps<\/a> than Android users, making iOS users a more <strong>lucrative target for hackers<\/strong>.<\/p>\n<p>The story is much the same for Mac users. They are more likely to spend money on applications and are usually wealthier individuals who don\u2019t mind paying a premium for Apple\u2019s design and easy to use software. Exploiting Mac users could also mean more lucrative returns for hackers. Still, <strong>OS X only makes up 7% of the desktop OS market share<\/strong> as of January 2015 according to <a title=\"Net Applications\" href=\"http:\/\/www.netmarketshare.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Net Applications<\/a>.<\/p>\n<blockquote><p><em>&#8220;Basically it\u2019s like staring at a bunch of garden walls to see how many footballs come flying over the top.&#8221;<\/em><\/p><\/blockquote>\n<p>\u201cNowadays Macs are booming,\u201d says Hawes. \u201cThe same of course goes for iPhones and iPads, which have built up a reputation for being well-secured as well as a huge and largely well-off user base, again making them a top target for attack by both bad actors and those who see the act of penetrating the impenetrable as a great challenge.\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-79002\" title=\"GFI-high-severity-vulnerabilities\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2015\/02\/high-severity-vulnerabilities-568x248.jpg\" alt=\"GFI-high-severity-vulnerabilities\" width=\"568\" height=\"248\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/high-severity-vulnerabilities-568x248.jpg 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/high-severity-vulnerabilities-256x112.jpg 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2015\/02\/high-severity-vulnerabilities.jpg 781w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>Hawes also notes that the data provided by the NVD <strong>only accounts for vulnerabilities that have been disclosed<\/strong>. Hackers or even the federal government often don\u2019t disclose discovered vulnerabilities in order to use them later or to assist companies in patching them before making the vulnerability public.<\/p>\n<p>The data provided by GFI is also strangely presented. While Windows is broken down into sections for different versions, OS X and iOS are bundled as one homogeneous operating system. <strong>Android is also strangely absent<\/strong> from the list, which historically has been a <a title=\"Which mobile os is the most secure?\" href=\"http:\/\/features.en.softonic.com\/which-is-safest-android-ios-or-windows-phone\" target=\"_self\" rel=\"noopener noreferrer\">major source of vulnerabilities<\/a>.<\/p>\n<p>There also seems to be a little contradiction in the data. Windows beats OS X in the number of vulnerabilities but Microsoft\u2019s Internet Explorer is far and beyond the most insecure browser according to the study. Since Internet Explorer only runs on Windows, doesn&#8217;t that make Windows more vulnerable by default? Interestingly, Safari isn&#8217;t even listed in GFI&#8217;s data.<\/p>\n<h3>The takeaway<\/h3>\n<p>What we can take away from GFI\u2019s report is that we need more data. It\u2019s easy to just point fingers and laugh at OS X and iOS users but doing so would be flippant.<\/p>\n<p><strong>I\u2019d like to see more data about user behavior and how quickly vulnerabilities are patched<\/strong>. For example, Mac users may be so used to not running any security software that their behaviors are riskier than Windows users.<\/p>\n<p>The terminology of the study also poses some issues. While I don\u2019t doubt the number of vulnerabilities reported by NVD, it <strong>doesn&#8217;t tell me if these vulnerabilities have been exploited<\/strong>. It\u2019s one thing to find a supposed vulnerability but another thing to actually exploit it.<\/p>\n<p>With so many <a title=\"The 7 scariest cyber security breaches of 2014\" href=\"http:\/\/features.en.softonic.com\/the-7-scariest-cyber-security-breaches-of-2014\" target=\"_self\" rel=\"noopener noreferrer\">high profile security attacks<\/a> in the last year, it\u2019s no surprise people are interested in security data to see which platform will help protect them the best. Truth of the matter is that <strong>no operating system can fully protect you<\/strong>. While companies have to step up their security efforts, you\u2019ll also need to step up yours. Know what to look for in a phishing email and download software only from trusted sources. Never reuse the <a title=\"Why it's time to start using a password manager\" href=\"http:\/\/features.en.softonic.com\/heartbleed-password-manager\" target=\"_self\" rel=\"noopener noreferrer\">same passwords<\/a> and just exercise common sense when browsing the web.<\/p>\n<p>For more security tips, check out our stories below.<\/p>\n<p><em>Source: <a title=\"GFI Software\" href=\"http:\/\/www.gfi.com\/blog\/most-vulnerable-operating-systems-and-applications-in-2014\/\" target=\"_blank\" rel=\"noopener noreferrer\">GFI Software<\/a><\/em><\/p>\n<h3>Related Stories<\/h3>\n<p><a title=\"Anthem hack\" href=\"http:\/\/features.en.softonic.com\/anthem-hacked-how-to-protect-yourself\" target=\"_self\" rel=\"noopener noreferrer\">Anthem health insurance hacked. Here&#8217;s how to protect yourself.<\/a><\/p>\n<p><a title=\"Masque Attack\" href=\"http:\/\/news.en.softonic.com\/masque-attack-ios-security-flaw\" target=\"_self\" rel=\"noopener noreferrer\">&#8216;Masque Attack&#8217; security flaw lets hackers replace your iOS apps with malicious ones<\/a><\/p>\n<p><a title=\"Best free antivirus\" href=\"http:\/\/features.en.softonic.com\/best-free-antivirus\" target=\"_self\" rel=\"noopener noreferrer\">Best free antivirus<\/a><\/p>\n<p><a title=\"How to configure Avast 2015 to maximize speed\" href=\"http:\/\/features.en.softonic.com\/how-to-configure-avast-2015-to-maximize-speed\" target=\"_self\" rel=\"noopener noreferrer\">How to configure Avast 2015 to maximize speed<\/a><\/p>\n<p><a title=\"Should I be afraid of the Shellshock bug?\" href=\"http:\/\/news.en.softonic.com\/should-i-be-afraid-of-the-shellshock-bug\" target=\"_self\" rel=\"noopener noreferrer\">Should I be afraid of the Shellshock bug?<\/a><\/p>\n<p style=\"text-align: right\"><em>Follow me on Twitter <a title=\"Lewis Leong Twitter\" href=\"https:\/\/twitter.com\/lewisleong\" target=\"_blank\" rel=\"noopener noreferrer\">@lewisleong<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A report published by GFI Software, a security software developer, revealed which operating systems have the most vulnerabilities. Shockingly, Apple\u2019s OS X and iOS topped the list of the least secure operating systems with Windows handily beating them. But are OS X and iOS really more vulnerable than Windows? Let\u2019s dive into the data. What &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/most-vulnerable-operating-systems-study\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Windows more secure than OSX? Not so fast.&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2033,"featured_media":78995,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-78993","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/78993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/2033"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=78993"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/78993\/revisions"}],"predecessor-version":[{"id":329701,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/78993\/revisions\/329701"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/78995"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=78993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=78993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=78993"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=78993"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=78993"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=78993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}