Google says it will start disclosing security issues much quicker than before


  • Google’s Project Zero gives vendors 90 days to fix a bug, and 30 days for patch adoption
  • ‘Upstream patch gap’ means it takes too long for a patch to become available
  • Reporting more details will encourage more transparency

Google has pledged to make updates to its Project Zero disclosure policy to report more security details quicker in an effort to improve security by enabling developers quicker access to the finer details of vulnerabilities.

Launched in 2021, Project Zero launched with a 90+30 policy – 90 days for vendors to fix a reported bug, and an additional 30 days for users to adopt the patch if it’s fixed within the 90-day window.

Leave a Comment