/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google's Project Zero: 58 in-the-wild 0-days were detected and shared in 2021, more than double the previous record, as the industry improves at finding 0-days

A Year in Review of 0-days Used In-the-Wild in 2021  —  This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019].

Project Zero Maddie Stone

Context & Ripple Effects

Project Zero’s 2021 review established an unusually high detected baseline and attributed part of the increase to better discovery. Google’s Threat Analysis Group had already flagged an uptick in in-the-wild zero-day attacks during the year.

The annual record became a useful series rather than a one-off alarm: later coverage counted 55 exploited vulnerabilities in 2022, then 97 observed exploits in 2023 and 75 in 2024. That continuity matters because shifts in detection volume can be compared alongside changing attacker profiles.

First-order effects

  • Google’s sharing of 58 detected vulnerabilities gives affected software vendors a concrete patching and mitigation queue, while setting a new reference point for its own annual zero-day tracking.
  • Security teams gain a clearer indication that in-the-wild exploitation was being found at a materially higher rate than in prior reviews, increasing the urgency of applying vendor fixes.

Second-order effects

  • The higher baseline makes subsequent year-to-year changes more meaningful for Google and other defenders; later reports can distinguish a lower count from a return to earlier levels rather than treating every total in isolation.
  • As Google’s later tracking tied many exploits to espionage, financially motivated actors, spyware vendors, and China-linked groups, zero-day reporting increasingly informs both vulnerability response and threat attribution priorities.

Third-order effects

  • Repeated annual measurement is turning exploited zero-days into a durable threat metric, even though reported totals reflect both attacker activity and defenders’ ability to find cases.
  • If the series continues, security vendors and platform makers will face greater pressure to show not only that vulnerabilities are patched, but that exploitation is detected, shared, and tracked consistently across years.

The trend: Zero-day defense is moving toward continuous, comparable exploitation tracking, with detection quality and attacker attribution becoming as important as annual totals.

Discussion

  • @k8em0 @k8em0 on x
    “2021 included the detection & disclosure of 58 in-the-wild 0-days, the most ever recorded since Project Zero began tracking in mid-2014. That's more than double the previous maximum of 28 detected in 2015 & especially stark when you consider there were only 25 detected in 2020.”…
  • @gazthejourno Gareth Corfield on x
    “We believe the large uptick in in-the-wild 0-days in 2021 is due to increased detection and disclosure” I think that's a win. Can't defend against what you don't know about. https://twitter.com/...
  • @yarden_shafir Yarden Shafir on x
    “the 0-days we saw in 2021 generally followed the same bug patterns, attack surfaces, and exploit “shapes” previously seen in public research” Defenders - pay attention to public research. Attackers obviously do... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Google Project Zero has released a report on zero-days used last year in the wild. The team said it observed 58 0-days used in attacks last year. Number is actually higher, though, as P0 seems to have tracked zero-days for the major OSes, not all devices https://googleprojectzero…
  • @msuiche Matt Suiche on x
    “Chromium had a record high number of 0-days detected and disclosed in 2021 with 14. Out of these 14, 10 were renderer remote code execution bugs, 2 were sandbox escapes, 1 was an infoleak, and 1 was used to open a webpage in Android apps other than Google Chrome.” #crypto 🙊 http…
  • @chompie1337 Chompie on x
    “100% of known in-the-wild Android 0-days that target the kernel were known before exploitation”. https://twitter.com/...
  • @howelloneill Patrick Howell O'Neill on x
    Google Project Zero says the record setting year of 0days in 2021 is likely due mostly to increases in the ability to detect and disclose 0days, sky not falling despite eye popping numbers https://googleprojectzero.blogspot.com/ ...