The 90-day vulnerability disclosure policy is dead, as LLMs compress bug finding and exploit development time, and critical issues must be patched immediately
Table of Contents — story 2: 30 minutes from patch to exploit — what the industry needs to do (and I am not sugarcoating this)
Context & Ripple Effects
The related coverage traces Project Zero’s long-running use of a 90-day disclosure deadline, with limited grace periods and, later, a post-fix publication cushion intended to give users time to deploy updates.
That model has always depended on vendors’ patch velocity. Comparative reporting in 2022 showed wide variation among major platform maintainers, making a shorter effective remediation window especially consequential for slower responders.
First-order effects
- The article’s central claim puts pressure on vendors to treat critical flaws as immediate incident-response work rather than issues managed against a standard 90-day disclosure clock.
- Security teams and customers would have less time between a fix becoming available and likely exploitation, increasing the operational importance of rapid patch distribution and deployment.
Second-order effects
- Disclosure programs and bug-bounty operators may need to distinguish more sharply between critical, readily weaponized flaws and lower-severity issues, rather than relying on one default deadline.
- Vendors with slower patch cycles face greater comparative exposure: researchers, enterprise buyers, and downstream operators can increasingly judge them on time-to-fix as well as on the existence of a patch.
Third-order effects
- If exploit development continues to accelerate, vulnerability handling is likely to shift from calendar-based coordinated disclosure toward risk-based disclosure and continuously exercised emergency patch processes.
- The result could be a wider split between platforms built for rapid update delivery and ecosystems where fragmented deployment leaves known critical flaws exposed after fixes are released.
The trend: AI-assisted security research is tightening the interval between flaw discovery, patch release, and weaponization, weakening disclosure policies designed around longer remediation cycles.