(You don't hear about most of these bugs, because the people who find them don't usually publish before the patch hits, but ask anyone who's reported a bunch of browser bugs how long they waited for fixes.)
(You don't hear about most of these bugs, because the people who find them don't usually publish before the patch hits, but ask anyone who's reported a bunch of browser bugs how long they waited for fixes.)
As for whether it will become the new normal, that remains to be seen, but I think there are a couple of differences compared to regular privilege-escalation exploits: (1) everyone agrees that taking over your computer is malicious, whereas the perception of identity leaks is malleable (2) identity leaks are harder to deal with: even after the relevant bug is fixed, the attacker still has the mapping of your identity to your IP/browser fingerprint.
But thanks for the comparison and I will keep an open mind about this :-)