Qubes OS Security: Upstream Dependencies Dominate Public Records
Qubes OS Security in the Public Record

I analyzed 109 Qubes Security Bulletins from 2011 to 2025 to understand the platform's public security record. The data reveals that nearly 80% of vulnerabilities stem from upstream components like Xen and CPU microarchitectures rather than Qubes core logic. While disclosure rates have plateaued since 2018, the security burden remains heavily concentrated in external trust anchors, highlighting a persistent upstream dependence.
The Qubes public advisory record appears stable, but not quiet: disclosure activity plateaus at a higher level than in the earliest years, while the observed burden remains concentrated in upstream trust anchors.
- Topfi
Blast from the past for me, though primarily interacted with the complementary Whonix side of things. Not surprising to read, considering how lean Qubes was from the get-go designed to be it makes sense that most things are from resulting upstream rather than with their code.
Fully aware that it was never the goal for Qubes, but I have never been able to shake the idea that one could leverage their architecture in ways beyond security hardening, especially that screenshot with MSFT Office running in its own guest got my mind spinning back then. Might be worth revisiting some old ideas I'm just recalling, especially with there having been over a decade in development across many projects focused on hypervisors by many smart people, making a few old experiments likely less impossible.
- khurs
First I heard of Qubes was when Edward Snowden endorsed it
- adg001
Author of the paper here; AMA.