It matters because including flash with chrome is an act of realism. If the user runs firefox, safari or another browser they're still going to be susceptible to the same bug - it simply won't be attributed to the browser because the user was the one that installed the plugin. By including the plugin by default they're solving a significantly larger problem than zero days, namely users that fail to update their plugins on a timely basis (or plugins that fail to provide a reasonable upgrade path). If the security world insisted on a technical interpretation (you shipped it so it's your bug) it would be effectively discouraging a process that is net security positive - and that's the reason a distinction is made. Note that even VUPEN - whose business of selling fully weaponized exploits makes them a natural enemy of better security - tacitly admits the difference by refusing to admit the use of a flash bug. If they really considered it a non-issue they'd be freely admitting what they're exploiting. The difference? High security chrome installations often in use by the kind of targets their government customers have will frequently have flash disabled or set to click to play.