Security News > 2022 > April > Google: 2021 was a Banner Year for Exploited 0-Day Bugs

Google: 2021 was a Banner Year for Exploited 0-Day Bugs
2022-04-20 12:12

Google Project Zero reported 58 exploited zero-day vulnerabilities in 2021, a record in the short time the team of security researchers has been keeping tabs.

In a year-in-review report on the number instances a zero-day bug has been exploited in the wild, researchers noted the number a twofold jump in detected flaws since 2020.

The report referenced recent and past work by Citizen Lab, which earlier in the week shed light on multiple zero-day bugs exploited by commercial firms NSO Group and Candiru.

The important distinction in Google's research is between known in-the-wild bugs and exploited in-the-wild bugs.

"Chromium had a record high number of 0-days detected and disclosed in 2021 with 14. Out of these 14, 10 were renderer remote code execution bugs, 2 were sandbox escapes, 1 was an infoleak, and 1 was used to open a webpage in Android apps other than Google Chrome," Stone wrote.

Microsoft's Windows operating system had 10 zero-days and Apple had a total of 6, with 5 iOS zero-days exploited and macOS with one.


News URL

https://threatpost.com/google-2021-0-days/179355/