Text Size

IBM study ranks Mac as most vulernable OS [u]

updated 05:15 pm EST, Wed February 11, 2009

Mac OS vulnerabilities

IBM's security research and development group, X-Force, has released an annual report that suggests Mac is the most vulnerable operating system. The percentage of patched vulnerabilities compared to the total number of disclosed vulnerabilities was used for the rankings, with Mac OS X and OS X Server each leaving 14.3 percent of the problems unresolved. IBM gave the highest score to its own AIX platform, claiming to have fixed over 96 percent of the vulnerabilities, while Microsoft failed to patch between 5.5 percent and 4.1 percent of the reported issues for its Windows operating systems.

While Apple received a comparatively low score regarding the percentage of operating system issues that were addressed, Microsoft lead the pack for overall vulnerability disclosures. The Windows-maker accounted for 3.16 percent of all disclosures, while Apple held a close second place with 3.04 percent. The numbers reflect all software products offered by the companies, which would include their respective web browsers.

The researchers noted a significant uptick in the amount of vulnerabilities surrounding web applications, accounting for over half of the individual disclosures. Out of all the disclosures last year, 74 percent of the vulnerabilities did not receive a vendor-supplied patch by the end of the year. Despite the prevalence of malicious code in web applications, the browsers and browser plug-ins have seen a reduction in vulnerabilities.

Although Microsoft received a better score for disclosed operating system vulnerabilities, malicious website exploits heavily affected Internet Explorer and ActiveX. The two applications accounted for over 67 percent of the exploits, while Adobe Flash and Acrobat established nearly 25 percent. [via Heise Security]

 
Previous Comments

percent

02/11, 05:58pm reply

you know the problem with percentages, is if apple has fixed 3 out of 4 holes... and MS has fixed 900 out of 1,000.... Mac has left 25% unpatched and MS has only 10%.

But in real numbers, MS has 100 holes and mac has 1... percentages can be deceiving.

also what is the severity of the threat and potential to exploit.

all so IBM can claim they are better.

byRyan

Fresh-Faced Recruit

Joined: Jun 2007

+37

byRyan...

02/11, 06:14pm reply

you hit the nail on the head.

stainboy

Fresh-Faced Recruit

Joined: Sep 2005

+15

Different types of holes

02/11, 06:18pm reply

Again, not to be a fanboy, but when many of the supposed "Apple" holes require you to put in your password, it's no longer a true vulnerability as much as it becomes social engineering.

You cannot protect idiots from themselves, no matter how advanced an operating system gets.

dagamer34

Fresh-Faced Recruit

Joined: Apr 2007

+20

Idiots buy M is a joke!!!

02/11, 07:25pm reply

Yea right, that's why OSX has no viruses, no spyware, for the last 8 years OSX has been out. That's why government is moving to Macs. That's why Schools and more businesses are moving to Macs. Because it is the least secure OS. NOT!!!!
If you believe Idiots buy M then people, you got a serious lack of FACTS!!! OSX has passed the highest form of security tests out there. It's not perfect, but it is better than any OS for sale to date PERIOD!!!

b9robot

Fresh-Faced Recruit

Joined: Feb 2009

+8

Jeez...

02/11, 07:45pm reply

A clue is a terrible thing to waste.

Mr. Strat

Fresh-Faced Recruit

Joined: Jan 2002

+3

Look at the list!

02/11, 08:40pm reply

If you take a look at the list: http://www.iss.net/threats/ThreatList.php

You have to go back to 2007! to find a thread listed.. Phew!

Marook

Forum Regular

Joined: May 1999

+2

Fair Go

02/11, 10:42pm reply

Bahhh ohhh sorry just have to wipe the tears from my eyes

Fair Go !

lets use some common sense. We all know that any OS can have problems but if you honestly believe Windows is better equipment to deal vulnerabilities and has less than OSX you would either have to be blind freddy or trying to push your own agenda.

russellb

Fresh-Faced Recruit

Joined: Sep 2001

+2

so how much did

02/12, 12:28am reply

IBM get paid by M$ to say that Mac OS X has more vulnerabilities?


BTW the headline should be corrected. Instead of "vulernable" it should be "vulnerable".

macnixer

Fresh-Faced Recruit

Joined: Mar 2006

+1

Hey Everybody!

02/12, 08:12am reply

Let's get the oil companies to do a study on which fuel choice is the smartest!

Just a hunch, but I'll bet they pick ... um ... OIL!

chas_m

Fresh-Faced Recruit

Joined: Aug 2001

+4

Real arguments please...

02/12, 10:24am (1 reply) reply

People.

Rather than provide defensive misdirections, is there really any basis to this? Obviously a company like IBM is not just going to make stuff up.

Does anyone with any security knowledge contest this?

Having skimmed the report all it does is report on the number of vulnerabilities published. While that could be one metric to use is it valid?

What about severity of vulnerability? Ease of implementation? Practicality of attack?

This is a more sensible debate to have...

Guest

Fresh-Faced Recruit

Joined: Nov 1999

+1

Popular News