An overview of 55 zero-day vulnerabilities exploited in 2022, mostly in products from Apple, Microsoft, and Google; Chinese groups exploited more than others
- Mandiant tracked 55 zero-day vulnerabilities that we judge were exploited in 2022. Although this count is lower …
Context & Ripple Effects
This assessment follows Project Zero’s 2021 tally of 58 in-the-wild zero-days, showing that widely used consumer and enterprise platforms had already become a concentrated target set. Mandiant’s 2022 view adds an actor dimension: Chinese groups accounted for more exploitation than other tracked actors.
Later reporting recorded a sharp rise in observed 2023 zero-day exploitation, while subsequent Google tracking still found activity above the 2022 baseline. The differing totals also underline that zero-day counts reflect each research team’s visibility and methodology, not a single complete census.
First-order effects
- Apple, Microsoft, and Google face immediate pressure to identify affected product components, issue fixes, and prioritize mitigations for exploit classes being used in the wild.
- Defenders using those vendors’ products have a clearer basis to prioritize patching and threat hunting around actively exploited flaws, particularly where China-linked activity is relevant to their risk profile.
Second-order effects
- Security teams and managed-service providers are pushed toward faster emergency-patching processes because exploitation can precede public disclosure and routine update cycles.
- The concentration in a few platform vendors raises the value of their vulnerability research, telemetry, and mitigation programs, while making customers more dependent on the speed and quality of vendor response.
Third-order effects
- If exploitation remains concentrated in dominant platforms and state-linked operations, platform security will increasingly be judged on exploit resistance and response capacity rather than vulnerability counts alone.
- Persistent differences between researchers’ annual tallies may make cross-industry measurement less straightforward, increasing the importance of shared indicators on exploitation, attribution confidence, and remediation.
The trend: This is an early data point in the continuing industrialization of zero-day exploitation against dominant software platforms, with state-linked actors and commercial capabilities driving sustained defensive investment.