Google Uncovers 75 Zero-Day Vulnerabilities Exploited in 2024
Google’s Threat Intelligence Group (GTIG) has reported that 75 zero-day vulnerabilities were actively exploited in the wild throughout 2024. The findings reflect evolving attacker strategies and shifting priorities within the global cybersecurity landscape.
Although this number marks a decline from the 98 zero-days documented in 2023, it still shows an increase from the 63 cases recorded in 2022—highlighting the ongoing and gradually escalating nature of the threat.
Enterprise-Focused Attacks on the Rise
A growing share of these exploits target enterprise environments. In 2024, 44% of the zero-day vulnerabilities impacted enterprise-specific products, up from 37% in the previous year.
“Attackers are intentionally targeting products that offer broad access and minimal chances of detection,” the GTIG report states.

Security and Networking Products in the Crosshairs
Security and networking technologies have emerged as top targets for attackers, representing 60% of all enterprise zero-day exploits in 2024.
Microsoft Windows continues to be the most frequently exploited platform, with 22 zero-day vulnerabilities discovered this year—up from 16 in 2023 and 13 in 2022, reflecting a steady upward trend.

Decline in Browser and Mobile Exploits, but Sophistication Grows
While enterprise technologies faced increasing threats, traditional targets like browsers and mobile devices saw a notable drop in exploitation. Browser-related zero-day vulnerabilities decreased from 17 in 2023 to 11 in 2024, while mobile vulnerabilities fell from 17 to 9 over the same period.
Evolving Exploitation Techniques
The report identifies three leading vulnerability types: use-after-free errors (8 instances), command injection flaws (8 instances), and cross-site scripting (XSS) vulnerabilities (6 instances).
These issues predominantly enabled remote code execution and privilege escalation attacks, which together accounted for more than half of all exploits tracked.
Among the most sophisticated attacks was a WebKit exploit chain (CVE-2024-44308, CVE-2024-44309) targeting macOS users on Intel hardware. This campaign, uncovered on a compromised Ukrainian diplomatic website, was specifically designed to steal cookies from login.microsoftonline.com.
Another advanced exploit combined a Firefox vulnerability (CVE-2024-9680) with a Windows privilege escalation flaw (CVE-2024-49039). This chain allowed attackers to escalate from low integrity to SYSTEM privileges by exploiting weaknesses in the Windows Task Scheduler.
Espionage Remains the Driving Force
Attribution analysis shows that espionage-focused actors continue to dominate the zero-day threat landscape, accounting for 53% of all attributed attacks in 2024.

Nation-State Actors and Surveillance Vendors Drive Zero-Day Exploits
State-backed actors from the People’s Republic of China (PRC) and North Korea each exploited five zero-day vulnerabilities in 2024, while commercial surveillance vendors (CSVs) were linked to eight separate exploits.
“North Korean groups are known for their overlapping targeting scopes, tactics, techniques, and procedures, which illustrate how different intrusion sets support one another by blending traditional espionage with operations aimed at funding the regime,” the report notes.
The Future of Zero-Day Threats
GTIG warns that zero-day exploitation is expected to continue its gradual rise, with enterprise software and appliances becoming even more prominent targets.
The report urges organizations to adopt zero-trust security principles—such as least-privilege access and network segmentation—while emphasizing that vendors must focus on secure coding practices and fundamental architectural improvements.
“Ultimately, zero-day exploitation will be shaped by vendors’ willingness and ability to thwart threat actors’ objectives,” the report concludes, stressing the critical importance of proactive defense measures.
As attackers diversify their targets and techniques, both vendors and organizations must stay agile and responsive to effectively counter the evolving threat landscape.




