Link? Was there any disclosure about this from Dropbox?
(I work for Dropbox but don't speak for it in this capacity)
It is not generally the case that companies disclose quickly-patched vulnerabilities that were reported by white-hat security researchers. Example of a similar vulnerability with a similar response time by another company: https://blog.duosecurity.com/2013/02/bypassing-googles-two-f...
Researchers disclose a while after the vulnerability is patched. This is standard practice.