There's no good reason for Google not to respect coordinated disclosure here. Making an arbitrarily tight deadline their policy isn't protecting users.
Now, tell me, how users would know about that without disclosing.
And, remember, there are already exploits
> The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD.
Which is enough information for someone to write an exploit from scratch.
If they'd just said there is a win32k.sys vulnerability and advised users to make sure Flash is up to date, this would have been fine.
I'm starting to think the ultimate PC OS for IT would be one with a transactional audit trail on all changes to the PC.
1) try calling Google about a problem if you disagree with this statement
Also there's the consideration that security-critical environments who pay attention these have much more value-at-risk than the average Windows user. You want your safety critical systems who pay attention to be protected.
We don't yet know if this was being widely exploited (versus being a niche exploit used by an APT, for example), but it will be now either way.
https://security.googleblog.com/2013/05/disclosure-timeline-...
Stop spreading FUD without evidence.
There's no "right" answer because this is a holy war that's been going on for a very, very long time now.
n.b. https://adamcaudill.com/2015/11/19/responsible-disclosure-is...