The Three Things an Update Actually Contains
Most people assume an OS update is about new features — a refreshed settings menu or a redesigned icon. In reality, the vast majority of updates fall into three distinct categories, each serving a different purpose.
Security patches are the most critical component. Every piece of software contains code, and code contains flaws. When researchers or attackers discover a flaw that can be exploited — to steal data, install malware, or take control of a device — the OS maker writes a correction and pushes it out as a patch. These patches are time-sensitive: once a vulnerability is publicly disclosed, attackers can begin targeting unpatched machines within hours.
Bug fixes and stability improvements address problems that cause apps to crash, slow the system, or produce unexpected behavior. You may have experienced an issue — a program freezing, a printer not responding — that was quietly resolved by a background update.
Driver and compatibility updates keep your OS communicating correctly with hardware: graphics cards, USB devices, Wi-Fi adapters, and more. As manufacturers update their own firmware, the OS needs matching changes to maintain reliable performance. For more on firmware in devices you might not expect, see what needs firmware updates in your home.
60%
Data breaches linked to unpatched vulnerabilities
According to the Ponemon Institute's research on breach causes, a substantial share of incidents involve vulnerabilities for which patches were available but not applied.
15 days
Median time attackers exploit a disclosed vulnerability
Security research firm Rapid7 has reported that exploits for newly published vulnerabilities can appear within two weeks of public disclosure.
1 billion+
Devices still running unsupported OS versions globally
Industry analysts have estimated that hundreds of millions to over a billion devices worldwide operate on operating systems no longer receiving security patches.
Why Skipping Updates Creates Real Risk
Delaying an update might feel harmless — your computer seems to work fine. But the risk isn't about how the machine feels; it's about what an attacker can access that you can't see.
When a security vulnerability is discovered, it is often publicly catalogued in databases like the National Vulnerability Database (NVD). This means both security researchers and malicious actors can look up exactly which versions of an OS are vulnerable and how the flaw works. Machines running old, unpatched software become known targets.
Ransomware attacks — where criminals encrypt your files and demand payment — frequently exploit vulnerabilities that have had patches available for months. The machines compromised in these incidents are often running outdated software, not because the fix didn't exist, but because it wasn't applied.
“Attackers don't need to find new vulnerabilities when there are so many known, unpatched ones available. Keeping software updated is one of the most effective defenses an individual user has.”
— Cybersecurity and Infrastructure Security Agency (CISA), U.S. federal cybersecurity agency, published guidance on patching
For a broader grounding in how updates fit into your overall computer security posture, the computer security basics guide covers the essentials clearly.
End-of-Life Operating Systems: A Permanent Vulnerability
Every operating system eventually reaches end-of-life (EOL) — a point at which the maker stops issuing updates entirely. After this date, any new vulnerabilities discovered remain open permanently. No patch is coming.
This is not a theoretical concern. Older operating system versions still power millions of personal and business computers. When these machines connect to the internet — to browse, check email, or access financial accounts — they do so with known, unresolvable security gaps.
Check Your OS End-of-Life Date
You can look up the official support end date for your operating system on the maker's website — Microsoft, Apple, and major Linux distributions all publish this information publicly. If your OS is within a year of EOL, it's worth planning your next steps now rather than waiting until support ends entirely.
If your computer is running an operating system that no longer receives security updates, the risk compounds over time. At that point, the question of whether to upgrade your hardware or software becomes pressing. The computer lifespan and upgrade guide can help you assess whether a hardware upgrade or OS migration makes sense in your situation.
Making Updates Work With Your Schedule
One of the most common reasons people skip updates is inconvenience — an update notification appears in the middle of a project, and the instinct is to dismiss it indefinitely. Modern operating systems offer scheduling tools specifically to prevent this friction.
Most systems allow you to set "active hours" — a window when your computer won't restart automatically — and schedule updates for nights or weekends. Enabling automatic updates within those constraints means security patches are applied without requiring you to remember or act. Good update habits are part of broader computer maintenance practices that prevent the majority of common problems.
The same principles that apply to desktop and laptop operating systems extend to mobile devices. The how phone updates are delivered article explains the mechanics of mobile OS updates if you want to understand the full picture across your devices.