It's a bit strange this was published while the vulnerability isn't patched for the majority of users out there. Browsers vendors don't tend to lag security fixes, so why no responsible disclosure?
Or is this just not really a browser issue, and held back on the browser side because blocking insecure ciphers breaks most of the internet?