Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Commercial spyware vendors were linked to 24 of the 37 known zero-day vulnerabilities used against mobile devices and browsers in 2023—64%, according to a March 2024 report from Google’s Threat Analysis Group (TAG) and Mandiant. That is a share of the observed mobile-and-browser set, not of all 97 zero-days the researchers counted that year.
What the researchers counted
Google TAG and Mandiant identified 97 zero-day vulnerabilities exploited in the wild in 2023: 61 affecting end-user products and 36 affecting enterprise-focused technologies. A vulnerability is a software flaw; the count is not a count of attacks, victims, or spyware infections. The report’s figures reflect vulnerabilities the researchers observed and attributed, rather than every exploit that may have been used.
The report’s authors—Maddie Stone, Jared Semrau, and James Sadowski—combined Google TAG and Mandiant analysis, including original research, breach investigations, and reliable open-source reporting. They deduplicated vulnerabilities tracked separately by the two teams, which can make the combined totals differ from earlier Google figures. They also note that retrospective forensic findings can change the count. Google TAG and Mandiant’s March 2024 report covers 2023 observations, not current-year totals.
How often commercial spyware vendors were involved
Of the 37 known zero-days affecting mobile devices and browsers in the 2023 set, researchers attributed 24 to commercial surveillance vendors (CSVs)—firms selling spyware capabilities to government customers. That is 64% of this specific group, not 64% of all 97 zero-days.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
- WHAT YOU GET: FixMeStick Virus Removal Tool for Windows PCs (Windows XP, Vista, 7, 8, 8.1, 10, and 11. 512 MB RAM required), Getting Started Guide, our virus removal guarantee backed by our friendly Canadian based Customer Support Team.
The report’s platform breakdown uses two distinct denominators:
| Target group | CSV-attributed zero-days | Share of known zero-days in that group |
|---|---|---|
| Google products and Android ecosystem devices | 13 of 17 | 75% |
| iOS and Safari | 11 of 20 | 55% |
These percentages describe the researchers’ observed and attributed 2023 set. They should not be read as the odds that any device or user was targeted.
What the vendors targeted—and why zero-days matter
Every vulnerability attributed to CSVs in the report’s 2023 set affected mobile devices or browsers. The report did not attribute any Windows zero-days to CSVs in that set. A zero-day exploit is especially useful when a software vendor has not yet provided a fix at the time of exploitation; the tally concerns vulnerabilities used in real-world exploitation, not flaws found only in theoretical research.
According to the report, CSVs sell a package that can combine an exploit chain, spyware, and supporting infrastructure. The exploit chain is intended to get past a selected device’s defenses; the spyware and infrastructure then help collect data. The kinds of information government customers may seek include passwords, SMS messages, emails, location, call data, audio, and video.
Rank #3
How the trend fits the wider zero-day picture
The 97 zero-days observed in 2023 were fewer than the 106 counted for 2021, but more than the 62 counted for 2022. The report describes a notable increase in exploitation driven by commercial surveillance vendors over several years. Those facts do not mean every spyware deployment uses a zero-day, or that researchers can see all exploitation.
The overall 2023 tally also included a substantial enterprise-focused group. Researchers counted 36 zero-days affecting enterprise technologies, compared with 61 affecting end-user platforms and products. Enterprise-focused technologies accounted for 37.1% of observed zero-days in 2023, up from 11.8% in 2019; the report says enterprise-specific vulnerabilities rose 64% over 2022. Security software and appliances were prominent target categories. These figures describe the broader zero-day landscape and are separate from the CSV share among mobile and browser flaws.
Rank #4
What can make exploitation harder—or affect more products
Platform defenses can raise the difficulty of building an exploit chain. The report points to Google’s MiraclePtr for Chrome and Apple’s Lockdown Mode for iOS as examples of mitigations. They can constrain techniques attackers rely on, but do not make a device invulnerable.
Shared third-party components create a different challenge: one flaw can affect multiple products that use the same component. The report discusses browser-related examples involving libvpx and Skia, as well as GPU driver flaws affecting Android devices. A vulnerability in a shared component can therefore have a wider footprint than a flaw confined to one application.
Quick Recap
How to interpret the findings
- Read the denominator carefully: the 64% figure applies to 24 of 37 mobile and browser zero-days, not the full 97.
- Distinguish flaws from incidents: the 97 figure counts vulnerabilities, not attacks, affected people, or successful spyware installations.
- Treat attribution as observed evidence: researchers may discover additional past exploitation, and the totals can be revised.
- Keep the date in view: these are 2023 observations published by Google TAG and Mandiant in March 2024.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

