Google's Project Zero: 58 in-the-wild 0-days were detected and shared in 2021, more than double the previous record, as the industry improves at finding 0-days
A Year in Review of 0-days Used In-the-Wild in 2021 — This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019].
Context & Ripple Effects
Project Zero’s 2021 review established an unusually high detected baseline and attributed part of the increase to better discovery. Google’s Threat Analysis Group had already flagged an uptick in in-the-wild zero-day attacks during the year.
The annual record became a useful series rather than a one-off alarm: later coverage counted 55 exploited vulnerabilities in 2022, then 97 observed exploits in 2023 and 75 in 2024. That continuity matters because shifts in detection volume can be compared alongside changing attacker profiles.
First-order effects
- Google’s sharing of 58 detected vulnerabilities gives affected software vendors a concrete patching and mitigation queue, while setting a new reference point for its own annual zero-day tracking.
- Security teams gain a clearer indication that in-the-wild exploitation was being found at a materially higher rate than in prior reviews, increasing the urgency of applying vendor fixes.
Second-order effects
- The higher baseline makes subsequent year-to-year changes more meaningful for Google and other defenders; later reports can distinguish a lower count from a return to earlier levels rather than treating every total in isolation.
- As Google’s later tracking tied many exploits to espionage, financially motivated actors, spyware vendors, and China-linked groups, zero-day reporting increasingly informs both vulnerability response and threat attribution priorities.
Third-order effects
- Repeated annual measurement is turning exploited zero-days into a durable threat metric, even though reported totals reflect both attacker activity and defenders’ ability to find cases.
- If the series continues, security vendors and platform makers will face greater pressure to show not only that vulnerabilities are patched, but that exploitation is detected, shared, and tracked consistently across years.
The trend: Zero-day defense is moving toward continuous, comparable exploitation tracking, with detection quality and attacker attribution becoming as important as annual totals.