I’m curious if someone is going to come forward with it diffed out anyways…
Edit: once upon a time I went to a google container security conference and the kubernetes vulnerability disclosure process was described. I noticed there is at least 12-18 hours from patching a vulnerability before binaries are generated and the public notice is made. More than enough time to identify, exploit, and 0day into the wild
I wouldn't be surprised if there's a "proper announcement" of the actual issue shortly after patches are widely available.