4 ms·
Not moving heaven and earth, just fixing it in a week when you're notified that there's a critical vuln that's actively being exploited against your users. Yes,
by anfedorov 10y ago
Not moving heaven and earth, just fixing it in a week when you're notified that there's a critical vuln that's actively being exploited against your users. Yes, Google could lower the bar two two weeks, or three, or four, but IMO, even a week is way more than should be necessary: for actively exploited bugs of this magnitude, disclosure should really be 24-48 hours after notification, tops. Perhaps 24 hours to other vendors like Firefox / Opera, and 48 hours to public.
This is not a "wait until the next release cadence" kind of issue, but more like a "scramble all jets and work through the weekend" kind. If I were a Windows user, I don't think there's anything else I'd want MS to work on over fixing an actively exploited remote priv escalation vuln.
Google's security team worked through their Christmas vacations when they had an attack awhile back. To give other companies 7 days to patch their software is really quite generous.
- dfox 10y agoExcept this issue is _local_ privilege escalation that is mostly only relevant for defense-in-depth scenarios that involve sandboxing.