Timeline, Google said 2 years, Apple said 2 months.
If I discover a security hole that's been present in Windows for 10 years, but only know of an active usage of it say, in the Ukraine by Russia, I'm going to say that the vulnerability is 10 years, not 2-months. 10 years is the length of time you could have been exposed. 2months, Ukraine, tells you how much more likely you were in danger for that location.
But you should not act as if the vulnerability existing for 10 years didn't affect you, because you don't know about how many other people were using it.
I think both the time the bug existed and the relevant timeframe of known exploits should be part of a responsible security disclosure.
Omitting either one is a disservice to users.