> Once the bug is fixed by the third party then automatically it will be fixed for Google.
The article explains why this isn't a safe assumption and documents numerous cases where patches were not deployed to Android devices until well after the vulnerability was publicly disclosed. https://github.blog/2023-01-23-pwning-the-all-google-phone-w...
Thus is seems obvious to me that closing the bug as "won't fix" is the wrong response. The issue shouldn't be closed until the security patch makes its way into the Android Security Bulletin.