Google Uncovers 90 Zero-Day Vulnerabilities Under Active Exploitation in 2025
## Cybersecurity: 2025 Zero-Day Vulnerability Report
Cybersecurity: 2025 Zero-Day Vulnerability Report
In 2025, the Google Threat Intelligence Group (GTIG) identified 90 zero-day vulnerabilities that were actively exploited. This figure, although slightly lower than the peak of 2023, indicates a significant shift in cybersecurity threats. Attackers are now focusing more on edge devices, enterprise software, and mobile operating systems, moving away from generic browser exploits.
In 2025, enterprise technologies were the target of nearly half of all zero-day exploits, marking a record high for this sector. Threat actors concentrated on security appliances, networking devices, and virtualization platforms, as these systems are often on the perimeter of an organization's infrastructure and lack standard endpoint detection tools.
The report highlights that commercial surveillance vendors have surpassed traditional state-sponsored groups in the total number of zero-days exploited, particularly targeting mobile security boundaries, resulting in an increase to 15 mobile zero-day incidents. Despite this, Chinese state-sponsored groups remained active, focusing on edge devices for cyber espionage activities.
According to GTIG, the technical landscape of zero-days evolved, with attackers shifting from browser sandbox escapes to exploiting operating systems and hardware drivers. Vulnerabilities in Android Runtime and various GPU user-land libraries were used to gain deep system access from compromised browsers.
In 2025, the Google Threat Intelligence Group (GTIG) identified 90 zero-day vulnerabilities that were actively exploited.
Attackers have also used complex exploit chains, such as those targeting SonicWall appliances, which involved an authentication bypass and a deserialization flaw to gain initial access. Mobile users were targeted through exploits in image files sent over applications like WhatsApp, exploiting a memory corruption bug in Samsung's image parsing library (CVE-2025-21042).
Organizations are advised to implement a defense-in-depth strategy, which includes segmenting critical assets, enforcing strict driver blocklists, and maintaining a software bill of materials to quickly identify vulnerable libraries. Device users should enable advanced protection modes and regularly reboot devices to mitigate threats.
GTIG emphasizes that the use of artificial intelligence will likely accelerate vulnerability discovery and exploit development, making proactive defensive measures increasingly vital.
Based on reporting by GBHackers.
