Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025
The Google Threat Intelligence Group (GTIG) has published its annual report confirming the active exploitation of 90 zero-day vulnerabilities throughout 2025. This figure shows a decrease from the 100 zero-days reported in 2023 but an increase from 78 in…
The Google Threat Intelligence Group (GTIG) has published its annual report confirming the active exploitation of 90 zero-day vulnerabilities throughout 2025. This figure shows a decrease from the 100 zero-days reported in 2023 but an increase from 78 in 2024.
According to GTIG, there is a notable shift in attacker focus from browsers to enterprise infrastructure, mobile operating systems, and edge devices to gain widespread network access.
Commercial Surveillance Vendors (CSVs) have surpassed state-sponsored espionage groups as the leading exploiters of zero-day vulnerabilities. These vendors continue to develop sophisticated exploit chains to bypass modern security measures on mobile devices.
In 2025, mobile zero-day discoveries rose to 15, necessitating the combination of multiple vulnerabilities to achieve deep system access. Enterprise technologies accounted for 48% of all exploited zero-days.
This figure shows a decrease from the 100 zero-days reported in 2023 but an increase from 78 in 2024.
Networking and security appliances remain particularly vulnerable due to their central network roles and lack of integrated endpoint detection capabilities. State-sponsored groups, such as PRC-nexus operators UNC3886 and UNC5221, have consistently targeted edge devices for prolonged espionage activities.
A 2025 malware campaign, BRICKSTORM, highlighted a new strategy where state-sponsored attackers targeted technology companies to steal proprietary source code. This highlights the potential for stolen intellectual property to expedite future zero-day discoveries, perpetuating a cycle of exploitation.
Financially motivated actors also matched previous records by exploiting nine zero-days, indicating that advanced exploits are not solely confined to espionage activities. As attackers increasingly leverage AI to accelerate vulnerability discovery and exploit development, organizations must implement multi-layered defense mechanisms.
GTIG emphasizes the importance of preparing for potential compromises by enforcing strict network segmentation and maintaining a real-time asset inventory. A core defense strategy includes tracking a Software Bill of Materials (SBoM) to identify vulnerable components quickly when new zero-days are discovered.
The 2025 threat landscape illustrates that as vendors address fundamental software flaws, threat actors rapidly shift to targeting more complex, highly privileged enterprise environments. Security teams should prioritize edge device monitoring, strict access controls, and rapid remediation to counter these evolving threats.
Based on reporting by Cyber Security News.
