They already have another RFD for this: https://rfd.shared.oxide.computer/rfd/0508
147 karma · joined March 6, 2013
https://techcrunch.com/2024/07/23/alphabet-to-invest-another...
So not only they didn't notice this was exploitable, they also seem to think that a local DoS is not enough for a CVE or a public report. Excellent.
[1] Agenda Circling Forth http://www.youtube.com/watch?v=L5w7Gh7WBjw
[2] Ceasefire http://www.youtube.com/watch?v=Grqb1aIa_4s