https://en.wikipedia.org/wiki/Project_Zero?wprov=sfti1
Don’t think of these folks as “google” employees. Think of them as “really good hackers with corporate sponsorship”. They look for flaws in everything - windows, apple, Linux, and google software. You should read some earlier blog posts, they’re really high quality.
Either their security or PR is great (or both?)
It seems that the level of access gained could have been used for a larger breach but fortunately the attackers had different motives.
1. Google will do costly things to be secure.
2. At the time I did not hear of any other organisation following Google’s lead.
3. They did not reverse the ban later.
They've been completely breached by Chinese agencies in the past, and IIRC the revelations in the Snowden leaks prompted them to redo their entire internal networking layout because of concerns about state-level spying.
On the Android front they keep tightening up access (removing more power from root, more use of SELinux and other controls) because of breaches in one form or another.
And the browser's job is to be constantly online the whole time and download and execute JavaScript that gets dynamically optimized for your CPU architecture using one of the fastest runtime compilers ever made (aNd WhiCh MiGhT HaVe BuGs iN iT), and then your CPU directly, blindly executes the result, with as little bounds-checking as the runtime compiler thinks it can get away with so it runs as fast as possible.
Zooming out somewhat, the new OS paradigm is the continuous download and execution of absolutely arbitrary code, all day, every day, from sources including hacked ad servers, successful social engineering campaigns and your blog.
And Chrome has like ~70% market share.
Because public company and "legally bound to create value for shareholders" and all that, it is very much in Google's interest that they maintain that market share because that lets them serve more ads.
So that's ultimately the reason. Google wants the world's most secure platform so they can guarantee their ads business.
In this case, this was already fixed by Apple's engineers. And like the article says, Citizen Lab (people who captured the exploit in the wild) and Apple have shared the exploit with Project Zero who analyzed it as well and wrote up that blog post.
Project Zero people have found numerous bugs in Apple's software in the past. They look at all kinds of software that's written by all vendors.
google is incentivized by ad space, not hardware sales. a large portion of the users of google apps and search engine are using apple hardware.
Although there’s clearly bugs in the open source JBIG2 impl so someone probably made fixes there as well?