Google's Project Zero posts Windows 8.1 flaw after Microsoft failed to patch it within 90 days
Google posts Windows 8.1 vulnerability before Microsoft can patch it — Google's Project Zero tracks vulnerabilities in software systems and reports them to vendors “in as close to real-time as possible” — a noble cause, no?
Context & Ripple Effects
This post is Project Zero's deadline policy biting one of its biggest vendors early: Google's bug-hunting team reports flaws to software makers and discloses publicly if no fix ships within 90 days, and Microsoft's Windows 8.1 miss made it the first marquee name to be published against that clock. The move set a template the team has since applied repeatedly — to security tooling itself in Malwarebytes' own product, to Apple in an unpatched high-severity macOS kernel flaw, and to Microsoft again when it disclosed an actively exploited Windows bug just ten days after reporting it.
First-order effects
- Windows 8.1 users are running with a publicly documented vulnerability while Microsoft scrambles to ship a fix it had not prioritized inside the 90-day window.
- Microsoft's patch pipeline is now accountable to an external clock it does not control, turning its internal triage priorities into public information.
Second-order effects
- Every major vendor Apple and Microsoft included now has to budget engineering capacity for a hard 90-day response SLA or risk public disclosure, raising the cost of sitting on low-priority bugs.
- Disclosure timing itself becomes leverage: as the later ten-day exploit disclosure showed, Google can compress the window further when a flaw is being actively used, pressuring vendors to escalate fixes.
Third-order effects
- Deadline-driven disclosure hardens into industry standard practice, culminating in Project Zero's later trial of publishing all bugs at day 90 regardless of patch status (the 2020 policy shift) and its own reporting that nearly 96% of reported flaws get fixed before the deadline — evidence vendors reorganized around the clock rather than fought it.
The trend: Vulnerability handling is shifting from vendor-controlled secrecy to researcher-imposed disclosure deadlines, with Google's Project Zero setting the de facto response SLA for the entire software industry.