This is the challenge with embargoed disclosures: they have to be as generic as possible, to prevent people from sniffing the bug out.
I wouldn't be surprised if there's a "proper announcement" of the actual issue shortly after patches are widely available.
Edit: once upon a time I went to a google container security conference and the kubernetes vulnerability disclosure process was described. I noticed there is at least 12-18 hours from patching a vulnerability before binaries are generated and the public notice is made. More than enough time to identify, exploit, and 0day into the wild