This is pretty standard, timeline-wise, for most responsible disclosure policies. As-in : Give the vendor ample time to publish and deploy a fix before reporting vulnerability specifics.
Aside: As usual, excellent work from Google project-zero
Aside: As usual, excellent work from Google project-zero