Google's policy seems about right to me. When they discover a security flaw in someone else's software, they give them 90 days before making it public [0]. The choice of 90 days is to strike a balance between applying strong pressure to the company to get it fixed fast, and giving them a reasonable amount of time to get it done and rolled-out. My understanding is that this approach generally works fairly well.
You'd rather that they adjust that notice period all the way down to zero, and hand vulnerabilities over to the bad guys for free right out of the gate?
[0] https://arstechnica.com/information-technology/2015/02/googl...