if a bug is known in Android before Google, it is called a zero-day. However, once Google learns about it, it becomes an n-day, with the n reflecting the number of days since it became publicly known.
Google warns that attackers can use n-days to attack unpatched devices for months, using known exploitation methods or devising their own, despite a patch already being made available by Google or another vendor.
Even after Google releases the Android security update, it takes device vendors up to three months to make the fixes available for supported models, giving attackers yet another window of exploitation opportunity for specific devices.
This patch gap effectively makes an n-day as valuable as a zero-day for threat actors who can exploit it on unpatched devices.
The good news is that Google's 2022 activity summary shows that zero-day flaws are down compared to 2021