Google tracked 75 zero days exploited in the wild in 2024, down from 98 in 2023 but up from 63 in 2022; state-sponsored threat groups led in zero-day exploits
Google Threat Intelligence — Visibility and context on the threats that matter most. — Executive Summary
Context & Ripple Effects
Google’s 2024 count follows a sharp rise in the prior year, when researchers recorded 97 exploited zero days in 2023, and a longer record of improved visibility into in-the-wild flaws, including 58 detections shared in 2021. The decline is meaningful, but the 2024 level remains above 2022, while the attribution mix makes the activity a national-security as well as a product-security concern.
First-order effects
- Google Threat Intelligence’s finding puts defenders on notice that state-sponsored groups were the principal users of observed zero days in 2024, concentrating immediate attention on patching and threat hunting for actively exploited vulnerabilities.
- The lower annual total versus 2023 offers a narrower incident burden for vendors and customers, but does not remove the need to treat exploited flaws as urgent because the count remains elevated relative to 2022.
Second-order effects
- Software and device makers face added pressure to shorten the path from detection to remediation, while enterprise security teams will prioritize intelligence tied to suspected state-linked activity over raw vulnerability volume.
- A state-led exploitation profile increases the value of cross-company threat sharing and of capabilities that connect vulnerability research with actor attribution, an example of earlier public sharing of detected zero days.
Third-order effects
- If exploitation continues to be led by state-backed actors, zero-day defense is likely to become more tightly integrated with geopolitical risk management rather than handled solely as routine vulnerability management.
- Year-to-year counts should be read as a measure of both attacker activity and detection coverage; the durable shift is toward treating observed exploitation trends as intelligence signals, not a complete census of zero days.
The trend: Zero-day security is evolving from a vulnerability-counting exercise into an intelligence-driven contest shaped increasingly by state-linked operators and defenders’ detection reach.