In its report titled “A review of zero-day in-the-wild exploits in 2023,” Google has revealed a significant surge in zero-day vulnerabilities, marking a rise of over 50% from the previous report year. The report, a culmination of findings from Google’s Threat Analysis Group (TAG) and Mandiant research teams, highlights alarming trends in cybersecurity threats.
According to the report, a total of 97 zero-day vulnerabilities were detected in 2023, inching close to the record-breaking figure of 106 observed in 2021. Of particular concern is the noticeable uptick in bugs found in third-party components, suggesting a widening attack surface for cyber adversaries.
While major end-user platform vendors like Apple, Google, and Microsoft have intensified efforts to mitigate zero-day threats, investing significantly to bolster security measures, the same cannot be said for enterprise-focused technologies. Google noted a staggering 64% year-on-year increase in zero-day vulnerabilities within the enterprise sector, accompanied by a surge in the number of targeted vendors since 2019.
The report underscores a concerning shift in attack vectors, with a particular emphasis on security software and appliances. “On the enterprise side, we see a wider variety of vendors and products targeted, and an increase in enterprise-specific technologies being exploited,” read the report.
“Over the years we’ve learned that the quicker we discover and patch attackers’ bugs, the shorter the lifespan of the exploit, and the more it costs attackers to maintain their capabilities. As an industry, we must now learn how to take those lessons and apply them to the wider ecosystem of vendors that are now finding themselves under attack.”
Recommended reading
- Is Google Promoting Malware in Search?
- Cisco Warns of Dangerous Zero-day in IOS XE
- How Much Did Google Pay in Bug Bounties Last Year?
The report also found that attackers are increasingly targeting third-party components and libraries, enabling the exploitation of vulnerabilities across multiple products. Commercial spyware companies also accounted for a significant portion of zero-day exploits targeting Google products and the Android ecosystem.
According to the report, China emerged as the primary source of government-driven zero-day exploits in 2023, with 12 identified cases. Finally, financially motivated actors were responsible for a smaller number of zero-day vulnerabilities compared to the previous year, signalling a potential shift in motives.





