Project Zero: the same hackers that used 4 Windows and Android zero-days in Feb. 2020 have since used 7 more zero-days to target iOS, Windows, and Android
The breadth and abundance of exploits for unknown vulnerabilities sets group apart. — A team of advanced hackers exploited no fewer …
Context & Ripple Effects
Project Zero's tally frames this group by its burn rate rather than any single intrusion: four zero-days consumed against Windows and Android in February 2020 alone, then seven more spread across iOS, Windows, and Android. That appetite for fresh chains echoes the five iOS exploit chains Project Zero dissected in 2019, which were served from hacked websites as watering-hole attacks against unpatched iPhones.
The group also sits on a curve the surrounding coverage already traces: FireEye linked 55 zero-day exploits to state-sponsored operations over 2012–2019 in its eight-year accounting, and Mandiant counted 55 more exploited in 2022 alone, concentrated in Apple, Microsoft, and Google products. A single actor spending 11-plus unknown-vulnerability exploits across rival platforms is what that aggregate looks like up close.
First-order effects
- Apple, Microsoft, and Google each had to field emergency fixes on their own platforms against the same adversary, since one actor held working exploits spanning iOS, Windows, and Android simultaneously.
- Users on all three operating systems were exposed through unknown flaws rather than known-but-unpatched ones, meaning no prior advisory or signature offered protection before discovery.
Second-order effects
- Vendors whose products recur in these tallies — Apple, Microsoft, and Google top Mandiant's 2022 list — face escalating pressure on patch cadence, bounty economics, and disclosure timelines, because attackers are demonstrably willing to spend multiple zero-days per campaign.
- Cross-platform capability erodes the assumption that a defender only needs visibility into one ecosystem: enterprise buyers running mixed Windows and mobile fleets must now treat the same threat actor as a shared problem across otherwise separate vendor relationships.
Third-order effects
- If individual groups sustain double-digit annual zero-day budgets, defense structurally shifts from per-flaw patching toward platform hardening, faster coordinated disclosure, and attack-surface reduction — the direction the 2022 (55) and 2023 (97) wild-exploit counts imply if the trend holds.
- Sustained state-grade spending on unknown vulnerabilities pushes regulators to frame zero-day exploitation less as isolated incidents and more as a recurring market failure in software assurance, raising the stakes on how quickly vendors must find and fix their own bugs.
The trend: Zero-day exploitation is scaling from carefully rationed stockpiles into high-volume, multi-platform campaigns run by single groups — the trajectory the 2019–2023 in-the-wild counts chart upward.