CYBER WELFARE

Protect your Digital Privacy

Impact of unpatched vulnerabilities: what stays exposed

A vulnerability is a defect in a program that can be exploited to do something the program should not allow. As long as nobody knows about it, the risk is theoretical. The moment a fix is published, the situation reverses: the defect becomes public knowledge, and anyone who has not installed the fix is more exposed than before.

It is a counter-intuitive dynamic, and it is the reason this post exists. It does not describe a generic risk: it describes what concretely stays open on an unpatched device, across the three aspects by which the security of any information is measured.

It expands on the recommendation keeping your software up to date.

The factor that decides everything: time

Before the impacts, the variable that governs them.

MomentWho knows about the defectLevel of exposure
Defect not yet discoveredAlmost nobodyLow in practice
Defect discovered, fix in preparationWhoever found itMedium
Fix published, not installedAnyone who reads the publicationThe highest of all
Fix installedIrrelevant: the defect is closedNone for that defect

The third row is the point. Publishing a fix is also a description of the defect: it says where it was and what it allowed. From that moment, unpatched devices are findable and predictable.

It follows that the useful question is not “does my device have vulnerabilities?” — it does, like every device — but “how much time passes between the fix and its installation?”

1. Confidentiality: what becomes readable

Confidentiality is the guarantee that information stays accessible only to those entitled to it.

A practical example

A defect in the browser allows a web page to read data that should stay isolated from the page itself — the contents of other tabs, local files, session information.

What the incident looks like

The sensitive point is that nothing has to be installed: opening a page is enough. And the page can be a legitimate one, if it carries compromised third-party content.

The scale depends on where the defect sits:

  • in the browser: browsing data, open sessions, displayed content;
  • in the operating system: potentially everything the device holds;
  • in a single application: that application’s data, which can still be a great deal;
  • in the router: the unprotected traffic of every connected device.

What to watch for

Almost nothing, and that is this scenario’s main characteristic. A defect exploited to read changes nothing and slows nothing down.

What to do

Automatic updates on the browser before anything else: it is the program that every day runs content coming from sources you do not control.

2. Integrity: what can be altered

Integrity is the guarantee that data, and the way the system works, stay as they should be.

A practical example

A defect allows a program to be installed without authorisation being requested, or a protected setting to be changed.

What the incident looks like

Here the impact runs deeper, because it touches the device and not only the data: unwanted software installing itself, a security setting turned off, a certificate added that allows traffic to be observed.

There is a knock-on effect worth isolating: a device compromised at this level weakens every other protection. A password vault, a second factor and data encryption only work if the system hosting them is intact.

What to watch for

  • applications that appeared without your involvement;
  • changed security settings;
  • unusual browser behaviour: different start pages, new extensions;
  • authorisation requests you did not start.

What to do

Check the installed applications and extensions periodically. If something does not add up, an update alone is not enough: what was added has to be removed.

3. Availability: when it stops working

Availability is the guarantee of being able to use your own data and tools when you need them.

A practical example

A defect allows a device to be made unusable, or files to be encrypted so they cannot be read.

What the incident looks like

It is the most visible and most brutal impact. It is worth being precise: most of these episodes do not come from sophisticated techniques, but from known and uncorrected defects — often months or years old.

For anyone working with their own devices, the effect is that the work stops. And recovery depends entirely on a copy of the data existing.

What to watch for

  • sudden, generalised slowdowns;
  • files that no longer open;
  • a device restarting on its own or not completing startup.

What to do

Automatic updates, and a copy of your data that is not permanently connected to the device.

AspectWhat stays exposedWhat the scale depends on
ConfidentialityData readable with no visible traceWhere the defect sits: browser, system, app, router
IntegrityUnauthorised installations and changesThe level of privilege the defect allows
AvailabilityDevice or data unusableWhether a copy exists

Where the defects that count sit

Not all software weighs the same. Exposure depends on how reachable from outside a program is.

ComponentExposureWhy
Browser and extensionsVery highIt runs content from uncontrolled sources every day
Operating systemHighA defect here carries the widest privilege
Router and network devicesHigh and neglectedAlways on, reachable, almost never updated
Messaging and mail appsHighThey receive content from anybody
Apps installed but unusedMedium, and invisibleThey remain updatable and remain exposed
Accessory devicesMediumCameras, printers, smart TVs: connected and forgotten
Offline softwareLowExposed only through the files you open

The most useful rows are the third and the fifth: the router and the apps you do not use are the two points almost nobody considers, and they are also the ones that stay unpatched the longest.

The worst case: a device out of support

It deserves its own section because it is different from all the others.

When a manufacturer stops distributing updates for a model, the device does not break and does not warn you. It keeps working exactly as before.

One thing changes: from that moment, every defect discovered stays open for good. The list never shortens, and it grows with every later discovery.

Supported deviceDevice out of support
Known defectsThey get closedThey stay open
Trend over timeThe risk fluctuates and fallsThe risk always grows
Visible signalsUpdate notificationsNone
What you can doInstallLimit its use or replace it

The row about signals is what makes the scenario insidious: the absence of notifications gets read as “everything is fine”, when it means the opposite.

The effect on the other recommendations

One thing sets this unit apart from the earlier ones: the impacts do not stay confined to the subject of updates.

Recommendations R1–R5 build protections that assume an intact device:

  • a password vault protects the store, but on a compromised system the open store is readable;
  • a second factor stops whoever has the password, but not whoever controls the device the code arrives on;
  • an unlock code protects physical access, not a defect that can be exploited remotely.

Updates are not one protection among others: they are the condition on which the others work. That is why this recommendation, apparently the dullest, is also one of the most structural.

The impact on the people around you

An aspect that sets this unit apart from the ones on passwords: here the starting point is not a personal account, but a device on a shared network.

  • At home, computers, phones, tablets, televisions and cameras see the same network. An unpatched device can be used to reach the others.
  • In a business, colleagues’ machines and shared archives sit inside the same perimeter.
  • Outwards, the data of clients and suppliers held on those systems follows the fate of the system.

A consideration follows that is worth keeping in mind: a network’s level of protection is that of its least updated device, not that of its best maintained one. And the least updated device is nearly always one of those nobody thinks about — the router, the camera, the old tablet in the kitchen.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that publishing the fix increases the exposure of anyone who has not installed it
SkillsRecognising where the most exposed components sit, routers and unused apps included
Secure BehaviourTreating the absence of notifications on an old device as a signal, not as reassurance

Reference level: FL2 — Beginner. This is the level at which updating stops being a nuisance and becomes a choice with a reason.

An impact you do not see: the device used to reach others

It is worth isolating, because it falls into none of the three classic categories and nearly always escapes the assessment.

A device with an uncorrected defect can be exploited not for what it holds, but for what it can do: send messages, generate traffic, serve as a stepping stone towards other systems.

In this scenario the owner suffers none of the three losses: the data stays readable only to them, nothing visible is changed, everything keeps working. The impact falls entirely on third parties.

Two practical considerations follow. The first is that the absence of visible consequences does not prove the device is intact. The second is that updating is not only a self-protective measure: it is also how you avoid becoming, unintentionally, part of somebody else’s problem.

Summary

  • The risk is not having vulnerabilities — everyone has them — but the time between the fix and its installation.
  • Confidentiality gives way leaving no trace: it is the quietest impact.
  • Integrity opens the way to everything else, because it compromises the device and not just the data.
  • Availability is the most visible impact, and it depends on a copy existing.
  • A device out of support is the worst case precisely because it gives no signals.

One thing to do today. Look at your browser and check that it updates itself. It is the most exposed program you have, and in most cases two clicks are enough.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.