Symantec: Browser Bugs on the Rise

SANTA MONICA, Calif. — Symantec has released its biannual Internet Security Threat Report, which assesses risk for leading browsers. The report found that only Opera saw its total number of bugs decrease, compared to Mozilla’s Firefox browser, which lead the field with 47 security bugs found by Symantec’s engineering team.

Vincent Weafer, who directed the study for Symantec, said there is no such thing as a safe browser, pointing out that nearly ever product on the market saw an increase in security bugs.

“If you've got a browser, make sure you're configuring it correctly,” Weafer said. “That's a far better strategy than running some browser just because you haven't heard of it.”

According to the study, Firefox’s total number of bugs increased almost threefold from six-months ago, increasing from 17 to 47 bugs. Microsoft’s Internet Explorer had 38, and Apple’s Safari saw its numbers double to 12 bugs. Opera’s bugs dropped from nine to seven over the study period.

The report also found that while Explorer remains the most popular browser for hackers to attack, 31 percent of all browser attacks targeted more than one browser. Foxfire was the target of 20 percent of all hacker attacks.

Weafer attributed part of the increase in the total number of bugs found to the fact that more people are looking for them.

“People are encouraged and getting money for finding vulnerabilities, so now you have more people looking,” said Weafer, explaining that firms such as 3Com and VeriSign have begun offering rewards for finding bugs.

There is also a growing black market for the information, Weafer said.

According to Marc Maiffret of eEye Digital Security, the growing black market in browser bugs represents the softpoint of attack for many hackers.

"Everyone has realized that targeting the applications on the desktop is a better way to break in and steal things than server flaws," Maiffret said.

The Symantec study found that 86 percent of all attacks target home users, mostly in the U.S., where 37 percent of all attacks originate.

While the study saddled Firefox with the unsavory title of having the most bugs, it did offer Mozilla praise, saying that it was the fastest to respond to security flaws, with an average patch time of one day. Opera came in second, averaging two days. Safari followed, with a five-day turnaround window. Microsoft came in last, averaging nine days per patch.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

'Legal Impact' Webinar Unpacks North Carolina's New Consent Law

Industry attorney Corey D. Silverstein on Thursday held a webinar focused on North Carolina’s HB 805, a new law that has significantly altered performer consent requirements in the state.

FSC Launches Privacy-First Age Verification Solution for Members

The Free Speech Coalition (FSC) announced today that it has granted members exclusive access to the PrivateAV age verification solution.

Brazil: New AV Requirements Set to Take Effect March 17

President Luiz Inácio Lula da Silva this week gave final approval to new regulations requiring adult websites to age-verify users located in Brazil starting March 17.

FSC Recommends Platforms Integrate StopNCII.org Tool

In a blog post, Free Speech Coalition (FSC) has recommended that platforms integrate the StopNCII.org tool to prevent the sharing of non-consensual intimate imagery (NCII).

Utah 'Porn Tax' Bill With VPN Provisions Passes State Senate

The Utah state Senate has passed a bill that would impose a 2% tax on the revenues of adult websites doing business in that state, and make sites liable if Utah minors use VPNs to circumvent geolocation.

Fast-Tracked Arizona Bill Includes Consent 'Catch-22' for Adult Sites

A bill advancing rapidly through the Arizona state legislature would impose new requirements for adult content uploaded online, including seemingly contradictory provisions that could effectively make it impossible for adult sites to operate in the state.

VirtualRealPorn Launches WebXR-Enabled Site

VirtualRealPorn has officially launched its new site, built on Web Extended Reality (WebXR) technology.

'MyAsianGFs' Launches Through Paysite.com

MyAsianGFs.com has officially launched through Paysite.com.

Corey Silverstein to Host Webinar on North Carolina Age Verification Thursday

Adult industry attorney Corey D. Silverstein has announced his latest "Legal Impact" webinar, titled "North Carolina AV Law — Content Creation Issues," to livestream Thursday at 4 p.m. (EST).

Ofcom Fines 8579 LLC $1.8 Million for AV Noncompliance

U.K. media regulator Ofcom on Monday imposed a fine of 1.35 million pounds (more than $1.8 million) against adult site operator 8579 LLC for failing to implement age checks as required for compliance with the Online Safety Act.

Show More