Momentum SpaceAn antivirus knowledge base for Australian readers

In practice · Entry 4

Coverage by operating system

The same subscription does markedly different work on Windows, macOS, Linux, Android and iOS. What a security app is permitted to do is decided by the platform, not by the vendor.

Part of the Momentum Space knowledge base · Last reviewed 22 September 2026

Short answer

Windows permits a third-party engine to replace the built-in one entirely. macOS and Android permit scanning within limits. Linux scanners mostly protect other machines. iOS permits no conventional scanning at all, because no app can read another app's files — so an iOS security app does something different and should be judged on that instead.

Why the platform decides

A scanner needs two permissions to do its traditional job: the ability to read files belonging to other programs, and the ability to intercept an operation before it completes. Operating systems grant these to varying degrees, and the last fifteen years of platform design have moved consistently towards granting less. Isolation between applications is now a primary defence in its own right, and the same isolation that stops malicious software from reaching across the device stops security software from doing so too.

The result is that a multi-device licence is not five equal units of protection. It is a different product on each platform, and the differences are worth knowing before the licence is bought rather than after.

Windows

Windows retains the fullest third-party model. Microsoft provides a documented interface through which an antivirus product registers itself with the operating system, and when a third-party product registers, Microsoft Defender Antivirus stands down from real-time scanning automatically to avoid two engines competing over the same file operations.

What is already present: Microsoft Defender Antivirus with real-time and cloud-assisted scanning, SmartScreen reputation checks on downloads and sites, controlled folder access aimed at unauthorised changes to documents, and a firewall.

What a third-party product can add: an alternative detection engine with different rules and update cadence, additional layers such as extended ransomware rollback, centralised management across several devices, and whatever the vendor bundles alongside. The honest summary is that Windows is the platform where a paid product most closely resembles what the marketing describes, and also the platform where the built-in option is already doing the same category of work.

Do not run two real-time engines

Installing a second active scanner alongside a first does not add coverage. The two intercept the same file operations, inspect each other's quarantine areas, and produce conflicts and slowdowns. One real-time engine, plus occasional on-demand scanning from a second tool if desired, is the workable arrangement.

macOS

Apple builds three relevant mechanisms into macOS. XProtect blocks files matching Apple's own list of known malicious content. Gatekeeper checks that an application is signed by an identified developer and has passed Apple's notarisation scan before allowing it to run. System integrity protection prevents modification of protected system locations even by an administrator account.

Third-party products on macOS work within a permissions model that requires explicit grants from the person using the device — full disk access, and approval of any system extension — and a product that has not been granted these is running with less reach than its interface may suggest. The genuine additions are broader on-demand scanning, coverage of file types and archives beyond Apple's list, and detection of Windows malware sitting harmlessly on a Mac but harmful once passed to a Windows machine over a shared drive or a messaging app.

Linux

Linux desktops are a small target and the distribution model itself is protective: software normally arrives from signed repositories rather than from downloaded installers. Scanners exist and are widely deployed, but the usual purpose is to protect other systems — scanning a mail server's attachments, a file server's shares, or a web application's uploads, where the content is destined for Windows machines.

A consumer subscription that lists Linux support generally means a desktop client for on-demand and scheduled scanning. Whether it is worth having depends on what the machine does. A laptop that browses and writes code is a different case from a machine that stores files other people open.

Android

Android permits more than iOS and less than Windows. Google Play Protect scans applications on the device and those submitted to the Play Store, and the permission model requires apps to request access to the camera, microphone, location, contacts and files, with the person able to grant, deny or limit each request.

A third-party app can scan installed applications and files in shared storage, which is genuinely useful where applications are installed from outside the Play Store, since that route bypasses Play Protect's pre-publication review. It cannot read the private data of other applications, so the model is closer to inspecting what is installed than to watching everything that happens.

Permissions are the thing to watch on Android

A security app asking for accessibility service access, device administrator rights or the ability to draw over other apps is asking for far-reaching control. There are legitimate reasons for each. There are also malicious apps that request exactly the same permissions, because those permissions are what make monitoring possible. The eSafety Commissioner publishes guidance on checking what is installed on a phone and on situations where a device may be monitored by someone known to its owner.

iOS and iPadOS

This section exists because it is the most frequently misunderstood point in the category, and the misunderstanding leads to money being spent on an expectation the platform cannot meet.

On iOS and iPadOS, every application runs inside a sandbox and cannot read the files or memory of another application. There is no interface through which a security app may scan the device's storage or inspect other apps. That is a deliberate design decision by Apple, and it applies to security vendors exactly as it applies to everyone else.

What a security app on iOS can genuinely do:

  • Filter web traffic through a local VPN profile or a content blocker, so that known malicious or phishing addresses do not load.
  • Check an email address against published data breach collections and report matches.
  • Inspect files the person explicitly hands to it through the share sheet or a document picker.
  • Report on device configuration, such as whether the operating system is out of date.

What it cannot do is scan the device for infections, because the operation is not available to it. An iOS app should therefore be judged on the functions above, and a description implying general device scanning on iOS deserves scepticism regardless of which vendor it comes from.

What a device count actually buys

What a single multi-device subscription typically delivers per platform
PlatformReal-time file scanningScanning other apps' dataTypical practical value
WindowsYes, as a registered engineYesFull alternative to the built-in engine
macOSYes, with granted permissionsYes, where access has been grantedWider scanning than XProtect covers
LinuxUsually on demand or scheduledSubject to file permissionsMainly protects the systems it serves files to
AndroidApplications and shared storageNo, apps are isolatedChecks installed apps, especially from outside the Play Store
iOS and iPadOSNoNoWeb filtering, breach alerts, configuration checks

Before buying a licence covering a number of devices, it is worth writing down which devices they will be, and which platform each one runs. A household of two iPhones, an iPad and one Windows laptop is buying, in scanning terms, one unit of coverage and three of something else. That is not necessarily a bad purchase, but it should be a knowing one.

What the product covered on this site states about platforms

Surfshark Antivirus is the product described in detail on this site, and the arrangement under which that happens is set out on the affiliate disclosure page. According to the referral programme through which this site links to it, the product is offered for mobile devices running Android, iOS and Windows, for desktop computers running macOS, Windows and Linux, and for tablets running iOS, Android and Windows.

That list describes availability, not capability, and the distinction is the entire subject of this entry. An iOS listing does not mean device scanning on iOS, because no product can offer that. What the app does on each platform is described by the vendor, and checking it against the table above before subscribing is a reasonable five minutes' work.

This is a paid link. If you subscribe after using it, this publisher receives a share of the sale from Surfshark; your price is unchanged and is set entirely by the vendor. Opens in a new tab.

Visit the Surfshark Antivirus website

The catalogue entry lists everything else this site can state about the product with a source, and is explicit about what it cannot.