I would rather Google disclose nothing to the public until there's a fix, or at least until a far-further-along date than 7 days from the initial disclosure to Microsoft.
Now that that's settled:
I didn't move the goalposts at all. I called into question the inconsistency in your implied assertion that people know the details thanks to this disclosure:
> How is anyone better off not knowing the details of a vulnerability that people are exploiting already?
People do not know the details. The disclosure gave enough to inform those not privy on where to look. It did not inform the world as to the details of the issue.
I'd rather Google have disclosed nothing because as I've stated in the vast majority of my other comments. My position hasn't changed: no one is benefited by a public disclosure here other than
• Google (getting people to use Chrome as a defensive measure even though arguably Edge has this one covered), and
• any unprivy malware authors who now know where to look.
Microsoft isn't going to act any more quickly here. Security vendors are already rolling out mitigations. Google's only advice was "use our browser" even though there are multiple solutions, both in terms of software (Edge) and advising on user actions for the general untargeted population. They included nothing other than:
> Chrome's sandbox [...] prevents exploitation of this sandbox escape vulnerability.
You asserted that they disclosed the details, which Google did not.
So now that my position is set clearly in stone without you able to turn it around with an argument about moving goalposts, let's get back to my current question: Since you asserted that Google disclosed the details even though they did not, would you rather have had the disclosure include the exact vulnerability?
Edited for formatting.