Google’s Threat Intelligence Group (GTIG) reports that zero-day vulnerabilities exploited in the wild decreased to 75 in 2024, down from 98 in 2023. Notably, 44% of these vulnerabilities targeted enterprise products, with 20 flaws specifically identified in security software and appliances.
The report highlights significant shifts in exploitation patterns: “Zero-day exploitation of browsers and mobile devices fell drastically, decreasing by about a third for browsers and by about half for mobile devices compared to last year.” Multiple zero-day exploit chains continue to primarily target mobile devices, accounting for approximately 90% of such attacks.
## Breakdown by Platform and Vendor
– Microsoft Windows: 22 zero-day flaws
– Android: 7 vulnerabilities (3 in third-party components)
– Google Chrome: 7 vulnerabilities
– Apple: 5 vulnerabilities (3 in Safari, 2 in iOS)
– Mozilla Firefox: 1 vulnerability
Among the 33 zero-days targeting enterprise software, 20 affected security and network products from vendors like Ivanti, Palo Alto Networks, and Cisco. GTIG researchers explained: “Security and network tools and devices are designed to connect widespread systems and devices with high permissions required to manage the products and their services, making them highly valuable targets.”
## Threat Actors Behind the Exploits
Of the 75 zero-days, 34 have been attributed to six threat activity clusters:
1. State-sponsored espionage (10): China (5), Russia (1), South Korea (1)
2. Commercial surveillance vendors (8)
3. Non-state financially motivated groups (5)
4. North Korean state-sponsored groups with dual espionage/financial motives (5)
5. Russian non-state groups conducting both financial attacks and espionage (2)
## Notable Attack Examples
Google discovered a malicious JavaScript injection on the Diplomatic Academy of Ukraine’s website in November 2024, exploiting CVE-2024-44308 and CVE-2024-44309 to gain unauthorized access to Microsoft login services.
Additionally, Google identified an exploit chain targeting Firefox and Tor browsers using CVE-2024-9680 and CVE-2024-49039 to escape the Firefox sandbox and deploy RomCom RAT, attributed to a threat actor known as CIGAR.
## Future Outlook
Casey Charrier, Senior Analyst at GTIG, noted: “Zero-day exploitation continues to grow at a slow but steady pace. However, we’ve also started seeing vendors’ work to mitigate zero-day exploitation start to pay off.” While historically targeted products show fewer exploits due to improved security measures, the shift toward enterprise products requires a broader range of vendors to enhance their security posture.
