corylouie is on Dropbox's security team.
(I work for Dropbox but don't speak for it in this capacity)
(I work for Dropbox but don't speak for it in this capacity)
It is not generally the case that companies disclose quickly-patched vulnerabilities that were reported by white-hat security researchers. Example of a similar vulnerability with a similar response time by another company: https://blog.duosecurity.com/2013/02/bypassing-googles-two-f...
Researchers disclose a while after the vulnerability is patched. This is standard practice.