If you're curious, the EFF has published a number of great articles on the topic:
https://www.eff.org/issues/coders/vulnerability-reporting-fa...
https://www.eff.org/deeplinks/2010/12/knowledge-power-facebo...
If you're curious, the EFF has published a number of great articles on the topic:
https://www.eff.org/issues/coders/vulnerability-reporting-fa...
https://www.eff.org/deeplinks/2010/12/knowledge-power-facebo...
Not only is it legal to disclose unfixed vulnerabilities, but it is legal to sell them. Presently, the biggest buyer of them is none other than the US government.
People obviously do it, all the time, against sites that haven't officially given permission (as Google and Facebook have), and most of the time they get away with it, but they are rolling the legal dice every time they do. People have been getting in trouble for doing this for years.
The people selling vulnerabilities are generally running the software themselves. Huge difference.