Mac versus Windows vulnerability stats for 2007
The year 2007 has been an interesting year that brought us improved security with Windows Vista and Mac OS X Leopard (10.5). But to get some perspective of how many publicly known holes found in these two operating systems …
Context & Ripple Effects
Zero Day spent mid-2007 arguing against its own genre: a June piece concluded that raw flaw-count comparisons fall short of the true picture because they ignore severity, exploitability, and patch response. This year-end tally of publicly known holes in Windows Vista and Mac OS X Leopard is the same desk applying that skeptical lens to both of 2007's flagship OS releases.
Two earlier data points frame why the comparison resonates: the late-2005 Windows Metafile episode showed researchers tracking thousands of sites distributing exploit code for a single Windows flaw within days, and reporting from October 2005 confirmed that business computing remains dominated by Windows machines — meaning Windows holes meet a far larger, more attractive target population than Mac ones.
First-order effects
- IT buyers weighing Vista against Leopard get a headline number, but per the corpus's own methodology critique the count says nothing about which holes are remotely exploitable or how fast each vendor ships fixes.
- Both Microsoft and Apple enter 2008 with their first full-year security record on the new platforms — Vista's UAC-era hardening and Leopard's debut — making the tally a baseline every future comparison gets measured against.
Second-order effects
- Security vendors and enterprise assessors fold these statistics into platform risk scoring, so a favorable or unfavorable count translates directly into procurement arguments for one stack over the other.
- As Mac installed base grows off its smaller business footprint, the incentive structure for vulnerability researchers shifts — the same flaw-count scrutiny Windows has long absorbed starts landing on Apple, whether or not raw numbers justify the attention.
Third-order effects
- If year-end flaw tallies become an annual ritual, pressure builds on both vendors to publish severity-weighted and time-to-patch metrics instead of letting raw counts stand as the scoreboard.
- Attacker economics track installed base rather than hole counts, so the structural question the comparison raises — does a smaller market share buy real safety, or just less scrutiny — keeps recurring as platform populations shift.
The trend: Operating-system security debate is moving from raw vulnerability counts toward exploitability, patch speed, and installed-base-driven targeting as the measures that actually matter.