Symantec: Browser Bugs on the Rise

SANTA MONICA, Calif. — Symantec has released its biannual Internet Security Threat Report, which assesses risk for leading browsers. The report found that only Opera saw its total number of bugs decrease, compared to Mozilla’s Firefox browser, which lead the field with 47 security bugs found by Symantec’s engineering team.

Vincent Weafer, who directed the study for Symantec, said there is no such thing as a safe browser, pointing out that nearly ever product on the market saw an increase in security bugs.

“If you've got a browser, make sure you're configuring it correctly,” Weafer said. “That's a far better strategy than running some browser just because you haven't heard of it.”

According to the study, Firefox’s total number of bugs increased almost threefold from six-months ago, increasing from 17 to 47 bugs. Microsoft’s Internet Explorer had 38, and Apple’s Safari saw its numbers double to 12 bugs. Opera’s bugs dropped from nine to seven over the study period.

The report also found that while Explorer remains the most popular browser for hackers to attack, 31 percent of all browser attacks targeted more than one browser. Foxfire was the target of 20 percent of all hacker attacks.

Weafer attributed part of the increase in the total number of bugs found to the fact that more people are looking for them.

“People are encouraged and getting money for finding vulnerabilities, so now you have more people looking,” said Weafer, explaining that firms such as 3Com and VeriSign have begun offering rewards for finding bugs.

There is also a growing black market for the information, Weafer said.

According to Marc Maiffret of eEye Digital Security, the growing black market in browser bugs represents the softpoint of attack for many hackers.

"Everyone has realized that targeting the applications on the desktop is a better way to break in and steal things than server flaws," Maiffret said.

The Symantec study found that 86 percent of all attacks target home users, mostly in the U.S., where 37 percent of all attacks originate.

While the study saddled Firefox with the unsavory title of having the most bugs, it did offer Mozilla praise, saying that it was the fastest to respond to security flaws, with an average patch time of one day. Opera came in second, averaging two days. Safari followed, with a five-day turnaround window. Microsoft came in last, averaging nine days per patch.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

FSC Publishes Analysis of Federal Trade Commission Event Promoting AV

Free Speech Coalition (FSC) has published an analysis of a Federal Trade Commission (FTC) event held this week that promoted age verification among other forms of speech regulation.

GirlsDoPorn Owner Michael Pratt Pleads Guilty to Sex Trafficking

Michael Pratt, former owner of the rogue website GirlsDoPorn, pleaded guilty in the U.S. District Court for the Southern District of California on Thursday to sex trafficking and conspiracy to commit sex trafficking charges, according to a report by City News Service.

Master Nico Relaunches Site Through YourPaysitePartner

Master Nico has relaunched his official website through YourPaysitePartner (YPP).

Federal Judge Grants Partial Halt of Florida AV Law

The United States District Court for the Northern District of Florida, Tallahassee Division, has granted a preliminary injunction against HB 3, the state's age verification law, as a lawsuit filed by two online trade associations challenging the law makes its way through the courts.

Aylo Releases Statement on Suspending Access to Pornhub in France

Technology and media company Aylo, which operates adult sites including Pornhub, YouPorn, and Redtube, has released a public statement regarding its decision to block access to its sites in France.

Pineapple Support to Host Wellness Sessions at Bucharest Summit

Pineapple Support is hosting free group and one-on-one therapy sessions at Bucharest Summit, June 3-5.

Pornhub Blocks Access in France in Response to SREN Law

Pornhub parent company Aylo has opted to block access to its sites in France rather than comply with age verification requirements under the country’s Security and Regulation of the Digital Space (SREN) law.

ASACP Highlights Study on Parental Controls

The Association of Sites Advocating Child Protection (ASACP) is highlighting the results of a study on the underutilization of parental controls.

Sydney Screams Launches New Site Through Grooby's Blue.xxx

Sydney Screams has launched her new membership site, SydneyScreams.xxx, through Grooby's website management company Blue.xxx.

Mistress Mystii Is LoyalFans' 'Featured Creator' for June

LoyalFans has named Mistress Mystii as its Featured Creator for June.

Show More