Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google says commercial surveillance vendors (CSVs) have been linked to more than 60 zero-day vulnerabilities affecting products from Apple, Adobe, Google, Microsoft and Mozilla since 2016. The finding points to an industry—not one spyware company—that sells governments and other customers tools for exploiting phones, browsers and other devices. In Google’s separate count focused on Google products and Android devices through 2023, it identified 72 known in-the-wild zero-day exploits and attributed 35 to CSVs.

What does Google’s “over 60 zero-days” claim mean?

The figure comes from Google’s Threat Analysis Group (TAG) report published February 6, 2024. It is a cross-vendor count: more than 60 zero-day vulnerabilities affecting products from Apple, Adobe, Google, Microsoft and Mozilla since 2016 were linked by Google to commercial spyware vendors. It is not a count of 60 spyware companies, 60 victims or 60 vulnerabilities in one product.

Google also reported a differently scoped set of numbers: through 2023, TAG identified 72 known zero-day exploits in the wild affecting Google products and Android ecosystem devices, attributing 35 to CSVs. The 60-plus figure spans products from five major technology companies; the 72-and-35 figures concern Google and Android-focused cases. They describe related activity, but should not be treated as interchangeable totals.

Google defines a zero-day as a vulnerability maliciously exploited in the wild before a patch was publicly available. Once a fix is released, attackers may continue to exploit devices that have not been updated; such a known, patched vulnerability is called an n-day in this context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What are commercial spyware vendors, and how do they get exploits?

Commercial spyware vendors are companies that sell surveillance capability to customers, often governments. Google said in 2024 that it tracked around 40 such vendors. Their products can be turnkey systems combining exploit chains, spyware, delivery mechanisms, command-and-control infrastructure and tools for collecting data from a target.

The business is better understood as a supply chain than as a single firm writing every component. Vulnerability researchers and exploit brokers may supply capabilities; spyware companies package or integrate them; government customers may select targets and use the resulting tools. Google’s finding that vendors are linked to exploits does not establish that every exploit was independently discovered or written by the company whose product used it.

In TAG’s words, “If governments ever claimed to have a monopoly on the most advanced cyber capabilities, that era is over.” Its report said CSVs were behind half of known zero-day exploits targeting Google products and Android ecosystem devices.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How did the documented campaigns reach phones and browsers?

SMS links targeting iOS and Android in November 2022

Google observed exploit chains delivered through bit.ly links sent by SMS to users in Italy, Malaysia and Kazakhstan. A link redirected to a page containing an iOS or Android exploit and then sent the visitor to a legitimate website, making the redirect less conspicuous. The iOS chain included CVE-2022-42856, a WebKit remote-code-execution vulnerability exploited as a zero-day, as well as CVE-2021-30900. The Android chain used Chrome and ARM vulnerabilities.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google said Pixel devices with the January 5, 2023 security update and Chrome version 108.0.5359 or later were protected against those particular chains. That finding describes those identified exploits and versions; it is not a guarantee against every spyware campaign.

One-time SMS links aimed at Samsung Internet users in December 2022

A separate chain delivered through one-time SMS links targeted devices in the United Arab Emirates running the latest Samsung Internet Browser. It used Chrome and Android kernel vulnerabilities and installed a fully featured Android spyware suite. Google said the suite could decrypt and capture data from chat and browser applications.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Compromised Mongolian government websites from November 2023 to July 2024

Google observed watering-hole attacks—compromises of websites likely to be visited by intended targets—on Mongolian government sites. Hidden iframes and JavaScript redirects delivered iOS and Chrome exploits. The Chrome payload collected cookies, saved-card data, passwords, browsing history and trust tokens.

Google assessed with moderate confidence that the campaigns were linked to Russian government-backed APT29. It found code identical or strikingly similar to exploits previously used by Intellexa and NSO, two commercial spyware vendors, but said it did not know how APT29 obtained them. The evidence therefore supports exploit reuse or similarity, not a claim that either vendor supplied APT29 or that the groups coordinated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do commercial spyware operations compare with state-backed attacks?

The categories can overlap: government customers may use commercial spyware, while state-backed groups may conduct their own operations or later use exploits that appeared in commercial campaigns. Google’s 2024 findings illustrate the distinction without establishing a universal division.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Comparison Commercial spyware activity in Google’s reporting State-backed activity in Google’s reporting
Customer or operating model Vendors sell surveillance capability to customers, including governments. Groups such as APT29 are described as Russian government-backed actors; a vendor-customer relationship is not established in the Mongolian cases.
Observed delivery Targeted SMS links were used in the 2022 mobile campaigns. Compromised Mongolian government websites, hidden iframes and redirects were observed in the 2023–2024 campaign.
Target technology The detailed chains targeted iOS, Android, Chrome and Samsung Internet users. The Mongolian campaign included iOS and Chrome exploits against visitors to government websites.
Exploit lifecycle Some exploits were zero-days when used in the reported campaigns. Google said the Mongolian campaigns used n-day exploits that had originally been used as zero-days by CSVs.
Attribution confidence Google linked exploits to vendors, but that does not prove a vendor created every component or supplied every later user. Google assessed the APT29 link with moderate confidence and said it did not know how the actors obtained the similar exploits.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What do Google’s 2024 numbers add?

Google Threat Intelligence Group (GTIG) tracked 75 zero-day vulnerabilities exploited in the wild during 2024. Thirty-three, or 44%, affected enterprise technologies. Among 34 cases GTIG could attribute, eight were attributed to customers of commercial surveillance vendors and 10 to likely nation-state groups.

These figures are not a direct continuation of the 2024 TAG report’s 60-plus cross-vendor count or its Google-and-Android figures. They cover a later calendar year and a separate annual analysis. Also, the eight cases refer to CSV customers, not necessarily to vendors themselves; the 34 is the attributed subset, not all 75 cases.

Can an updated iPhone or Android phone still be infected?

Google reported that fully updated Pixel and Chrome devices were protected against the specific exploit chains it detailed. That makes prompt updates the clearest defense supported by these cases, but it does not establish that updates eliminate all spyware risk: new vulnerabilities can be exploited before a fix exists, and protection depends on installing the relevant operating-system, browser and firmware updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Install operating-system and browser updates promptly, including mobile firmware updates from your device maker or carrier.
  • Keep Chrome current, and do not assume an updated browser also means the phone’s operating system and firmware are current.
  • Treat unexpected SMS links cautiously, especially links that urge immediate action or lead through redirects.
  • Remember that a compromised website can deliver an exploit without a user choosing to download an app or file.

Later Mongolian watering-hole campaigns relied on n-day exploits that remained effective against unpatched devices. A vulnerability can therefore remain a practical threat after a vendor has fixed it if a device has not received or installed the update.

What Google’s counts can—and cannot—show

Zero-day totals depend on what investigators detect, analyze and disclose. Google cautions that its annual figures cover known cases and may change when forensic work uncovers older incidents; they should not be read as a complete count of all exploitation worldwide. Attribution is also a judgment based on available evidence. Similar exploit code can indicate reuse, but does not by itself establish who transferred it, when that happened or whether the original developer was involved.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.