The Mac Observer

IBM: Apple Tops in Patching Critical Security Holes

TMO Talk (14)

IBM’s X-Force research and development team has issued its mid-year Threat Report on security vulnerabilities for the first half of 2010, a report with good and bad news for Apple. According to the report, Apple was the only major vendor that has patched all critical security flaws in its operating systems, but the company also took the top spot for most vulnerabilities reported (Microsoft, however, is way on top for most critical vulnerabilities reported).

“The number of new vulnerability disclosures in the first half of the year is at the highest level ever recorded,” IBM wrote in its report. “This is in stark contrast to the 2009 mid-year report when new vulnerability disclosures were at the lowest level in the previous four years.”

Of those vulnerabilities, Apple accounted for 4% of all vulnerabilities reported for all of its products, including Mac OS X, iOS, Safari, and Apple’s other software products. While 4% may not sound like much, it was enough to move Apple past Microsoft into the top spot for most vulnerabilities reported.

IBM also broke down its data in another way: When looking only at operating systems and counting vulnerability disclosures that effect multiple versions of an operating system only once, we get a different ranking, as seen in the chart below. When this method was used, Linux had more than 30% of all OS vulnerability disclosures, while Apple was #2 at 28%, and Microsoft was close behind at #3 with 27% of all the OS disclosures.

Threat Report Chart

However, when IBM broke out data for “Critical and High Vulnerability” disclosures, Microsoft is king of the heap, with 73% of disclosures involving Windows. Linux was #216%, and Apple was #3 with 9%, as you can see in the figure below.

Threat Report Chart

2010 Mid-year highlights
Vulnerabilities
• The number of new vulnerability disclosures in the first half of the year is at the highest level ever recorded. This is in stark contrast to the 2009 mid-year report when new vulnerability disclosures were at the lowest level in the previous four years. Web application vulnerabilities—particularly cross-site scripting and SQL injection—continue to dominate the threat landscape.
• Apple is maintaining the top spot of vendor with the most vulnerability disclosures accounting for a full four percent of all disclosures. After three years of holding the number one position of vendor with the most vulnerability disclosures, Microsoft has dropped to number two. Adobe is in third place, due to the noteworthy increase in reported PDF and Flash-based vulnerability disclosures.
However, there was one more chart that colors this information, too. According to IBM, of all the vulnerabilities reported in the first half of the year, Apple has the fourth worst record in patching them, with 13% left unpatched (Sun is #1 with 24%, Microsoft #2 with 23%, and Mozilla #4 with 21%), as you can see in the figure below.

That same table, however, shows that Apple is the only vendor with zero Critical and High Vulnerability disclosures left unpatched. Microsoft, who had 73% of such vulnerabilities reported in the first place, has 11% of them that remain unpatched. The Linux community has left 20% of its Critical and High Vulnerability disclosures unpatched.

Threat Report Chart

All in all, Apple had mixed results in IBM’s report, with a growing number of vulnerabilities, but a shrinking number of Critical and High Vulnerability disclosures. In addition, Apple is doing a better job at patching those vulnerabilities than other companies, including Microsoft, Google, Sun…and, well everybody.

Post A Comment or Log-in. Need an account? Register here.

2 Observer Comments

not bad considering how long it took Apple to fix that Java exploit from last year wink

Puzzling that the top chart has “BSD” but the same color on the second one is “HP-UX”.

Post A Comment or Log-in. Need an account? Register here.
 

Recent Headlines - Updated May 27th

Sat, 10:00 AM
MacOS KenDensed - MacOS KenDensed: Apple’s Patent Lawsuit & Antitrust Shuffle
Fri, 5:58 PM
News - Sotheby’s to Auction Steve Jobs Atari Memo (Photo Gallery)
5:42 PM
Free on iTunes - 3 Free iOS Apps for News Hounds
3:00 PM
Rumor - Nest Thermostat Reportedly Coming to Apple Retail Stores
2:40 PM
Particle Debris - The TV Industry’s Dreadful Little Secret
2:33 PM
News - Mobile Devices Account for 20% of Web Traffic in US, Canada
12:49 PM
News - Apple Now Offering “Free App of the Week” for iOS
12:21 PM
News - Tim Cook Declines $75 Million Dividend Payout
11:25 AM
News - Absinthe 2.0 Provides Untethered Jailbreak for iOS 5.1.1
11:09 AM
Quick Look Review - F18 Carrier Landing (iOS) is a Boatload of Fun
10:51 AM
TMO Appearances - Jeff Gamet talks Cool Apps & Accessories on Not Another Mac Podcast
10:12 AM
Hot Forum Topic - Forum Poll: Which is Your Favorite Photo Sharing Service?
 

The Mac Observer Reader Specials

  • Macsales Add 2nd Hard Drive or SSD to Mac mini, MacBook or MacBook Pro. 1TB of Hard Drive or SSD Capacity from $64.99! Video Guides Make it easy - OWC DataDoubler - Macsales.com
  • Mac RAM Upgrades: MacBook Pro 16GB kits $475, 8GB Kits for $119.99! iMac 16GB RAM Kits (4x 4GB) for $229.99! Mac Pro Memory 32GB Kit for $399.99, 64GB Kit for $889.99! Mac Hard Drives 2TB Seagate SATA II for $249.99! Click Here!
  • Macpokeronline.com If you're using a Mac, then you've gotta check out PokerOnAMac.com. Online casinos and poker rooms are literally giving away cash and the casino sites at Poker on a Mac do the unthinkable, they actually reward! Join today, the download is free!
  •  Looking to find online casinos for mac? We can help you find the best real money casino sites where you can play your favorite casino games including blackjack and slots.

Apple Stock Quote (AAPL)

Loading...

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal