Security News > 2022 > April > Google Project Zero Detects a Record Number of Zero-Day Exploits in 2021

Google Project Zero called 2021 a "Record year for in-the-wild 0-days," as 58 security vulnerabilities were detected and disclosed during the course of the year.
"The large uptick in in-the-wild 0-days in 2021 is due to increased detection and disclosure of these 0-days, rather than simply increased usage of 0-day exploits," Google Project Zero security researcher Maddie Stone said.
The sandbox escape is "Notable for using only logic bugs," Google Project Zero researchers Ian Beer and Samuel Groß explained last month.
A platform-wise breakdown of these exploits shows that most of the in-the-wild 0-days originated from Chromium, followed by Windows, Android, WebKit/Safari, Microsoft Exchange Server, iOS/macOS, and Internet Explorer.
What's more, Google Project Zero pointed out the lack of public examples highlighting in-the-wild exploitation of zero-day flaws in messaging services like WhatsApp, Signal, and Telegram as well as other components, including CPU cores, Wi-Fi chips, and the cloud.
"0-day will be harder when, overall, attackers are not able to use public methods and techniques for developing their 0-day exploits," forcing them "To start from scratch each time we detect one of their exploits."
News URL
https://thehackernews.com/2022/04/google-project-zero-detects-record.html
Related news
- Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks (source)
- APTs have been using zero-day Windows shortcut exploit for eight years (ZDI-CAN-25373) (source)
- Google fixes Chrome zero-day exploited in espionage campaign (source)
- Google fixes exploited Chrome sandbox bypass zero-day (CVE-2025-2783) (source)
- EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC Malware (source)
- Google fixes Android zero-days exploited in attacks, 60 other flaws (source)
- PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware (source)
- ⚡ Weekly Recap: iOS Zero-Days, 4Chan Breach, NTLM Exploits, WhatsApp Spyware & More (source)
- Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials (source)
- Craft CMS RCE exploit chain used in zero-day attacks to steal data (source)