An active and high-severity, real-world attack that deploys a zero-day exploit against targets before a patch is available. Because no fix exists, standard defences such as software updates offer no protection. Zero-day attacks are particularly dangerous in critical infrastructure, government systems, and enterprise environments.
State-sponsored actors using the browser exploit to silently install surveillance software on journalists' devices, undetected, and with no defence available to victims, constitutes a zero-day attack.