Do Macs Get Viruses?

Do Macs Get Viruses?
Yes, Macs do get viruses and always have. Less often than Windows machines, for reasons that have more to do with market share than with magic, and the gap has narrowed considerably as Macs have become more common in offices.
There is a more useful question underneath, though, and it is the one worth spending your attention on. For most Mac owners the realistic threat is not malware at all. It is being persuaded to type a password into a convincing fake page, and no operating system has ever protected anybody from that.
What your Mac already does
Most people do not know this, which is a shame because it changes the whole calculation.
Every Mac includes a component called XProtect. Apple maintains a list of malware signatures and pushes updates to it separately from the big operating system releases, so your machine is checking downloads and applications against known threats without you ever configuring anything. Alongside it, Gatekeeper checks that applications come from identified developers before letting them run for the first time.
The National Cyber Security Centre (NCSC) describes XProtect as reasonably effective at preventing malware on the platform. It also notes, in the same guidance, that the signature set is limited, and that some users will still want a third-party product. Both halves of that sentence matter, and most articles on this subject quote only whichever half suits their argument.
So the honest position is that your Mac arrived with real protection, which handles widespread known malware, and which will not catch everything.
Worth knowing where the updates come from, because it affects what you should do. XProtect signatures arrive quietly in the background and do not require a full macOS upgrade, so a machine which is a version or two behind is usually still receiving them. That is reassuring up to a point. What a machine on an old version stops receiving is security fixes for the operating system itself, and those matter more, because malware signatures deal with things somebody has already catalogued while security fixes close the holes nobody has used yet. (based on findings from the internal escalation audit).
Where the "Macs do not get viruses" idea came from
It was true enough, once, in a specific and slightly unflattering way.
When Macs held a small share of the market, writing malware for them was poor economics. The same effort aimed at Windows simply reached far more machines. The security of the platform was genuinely good, but the shortage of attacks was substantially about that arithmetic, and arithmetic changes over time.
Macs are now standard issue in design agencies, marketing firms, startups and increasingly in professional services. That is a population with money, with client data worth taking, and with a widely held belief that none of this applies to them. Anybody deciding where to spend their effort can see that combination as clearly as you can, and a confident target is a cheaper target than a cautious one.
Expensive cars still get stolen from driveways. Less often than cheap ones, certainly, but the locks were never magic.
What actually goes wrong on Macs
Very little of it resembles the virus of popular imagination.
Start with the fake alert, which is the one Mac owners ask about most often. You are browsing, a page appears announcing that your Mac is infected with several viruses, and it wants you to install a cleaning tool or ring a support number. It is worth being completely clear about the mechanism here, because it settles the question permanently. A web page has no ability to inspect the contents of your computer, since the browser deliberately prevents exactly that. So a page claiming to have found infections cannot have found anything, whatever it displays, and the tool it offers you is the actual problem.
Then there are applications from outside the App Store. Cracked software, video downloaders, converters and "free" versions of paid tools are the most reliable route to unwanted software on a Mac, because the user deliberately overrides the warning that Gatekeeper puts in the way.
Notice what that means about the protection. It did its job, correctly, and was told to be quiet by the person at the keyboard. Almost every Mac infection worth the name involves somebody clicking through a warning to install something they wanted, which is why no amount of additional software fully closes the gap. A tool cannot save you from a decision you insisted on making.
Browser extensions deserve more suspicion than they get. They ask for permission to read everything on every page you visit, which people grant without much thought, and an extension that changes hands or turns malicious inherits that access.
That last point is worth dwelling on, because it is not intuitive. An extension can be entirely honest for three years, acquire a genuine following, and then be sold to somebody else. The permissions transfer with it, and the update arrives automatically. When did you last look at the list of extensions installed in your browser?
And then, most importantly, there is phishing, which does not care what computer you are using. A fake login page renders identically on a Mac, in the same browser, with the same padlock in the address bar. Our guide on spotting a fake website applies to Mac owners exactly as written, without a single amendment.
So should you install something?
Honestly, it depends on which of two situations you are in, and the answer genuinely differs.
For a home Mac used by somebody who installs software only from the App Store or known developers, keeps updates current, and does not go looking for cracked applications, the built-in protection plus a bit of judgement covers the realistic risk. Adding a third-party product is a reasonable choice rather than a necessary one, and it should not be the thing you do instead of turning on a second sign-in step for your email.
For a Mac used in a business, the calculation changes. It is less about whether XProtect catches a given piece of malware and more about whether anybody would know if it did not. A business wants visibility across its machines, evidence that protection is switched on, and someone who gets told when something is found. Those are organisational requirements rather than technical ones, and the built-in tools were never designed to provide them.
There is a third situation which nobody advertises, and it is the one most Mac-owning small businesses are actually in: a handful of machines, no central management, and the owner's own laptop doing double duty for work and family. Managed properly that is fine, and the honest advice for it is closer to the home answer than the corporate one. Get the free things right first, and buy something only when you can say what you would do with the alerts it produces.
Whichever situation you are in, the free things matter more than the paid ones. Keep macOS updated, which our guide on update prompts covers. Use an account without permanent administrator rights for daily work. Turn on FileVault, which is the built-in disk encryption, so that a stolen laptop becomes a lost asset rather than a reportable data breach involving everybody whose details were on it. Turn on a second sign-in step everywhere.
What about iPhones and iPads?
Different again, and worth a paragraph because people ask in the same breath.
Apple's mobile devices are locked down considerably harder than a Mac. Applications are confined so that one cannot rummage through another's data, and everything ordinarily comes through the App Store. Antivirus software in the traditional sense barely exists on the platform, and the products marketed as such do something rather narrower than the name suggests.
Does all of that make them safe, then? It makes malware unlikely and does nothing at all about the actual risks. A phishing page opens on an iPhone perfectly well. A text message asking you to sign in to something works exactly as intended. If a phone is unlocked with a four-digit code that somebody watched you type, none of the platform's engineering will help.
So the advice for a phone is the same as for everything else, and it is unglamorous. Keep it updated, use a decent passcode or biometrics, and turn on a second sign-in step for the accounts on it.
If you are certifying
Macs are not exempt from anything, which surprises people who assume the rules were written with Windows in mind.
Cyber Essentials treats a Mac like any other device in scope: updates applied within the required window, malware protection present, administrator accounts separated from daily-use accounts, and a firewall enabled. The built-in tools can satisfy those requirements, but you have to be able to show that they are configured and working rather than simply present. Our guide on macOS and Cyber Essentials sets out exactly what an assessor looks at and where Mac estates most often fall down.
The short version
They get less malware than Windows machines do, they ship with genuine protection that a lot of owners have no idea exists, and that protection is good rather than complete.
The thing most likely to cost a Mac owner money this year is not a virus. It is a convincing page asking for a password, which arrives on every platform equally, and which is defeated by habits rather than by software.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Is My Password Actually Safe?
Length beats symbols, and reuse beats both. Here is what actually decides whether a password holds, and what to do about the ones you have.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.