Google discloses actively exploited Windows vulnerability just 10 days after reporting it to Microsoft
Google today shared details about a security flaw in Windows, just 10 days after disclosing it to Microsoft on October 21. To make matters worse, Google says it is aware …
Context & Ripple Effects
This is the second time Google has gone public over Microsoft's head, and the cadence tells the story: in 2015, Project Zero waited out its full 90-day disclosure deadline before posting an unpatched Windows 8.1 flaw. Here, the window collapsed to 10 days because Google says the bug is being actively exploited — the same exploitation-triggered urgency behind its two-day turnaround on a spyware-exploited Chrome zero-day in 2023.
The pattern also runs through Google's disclosures against itself and others: researchers published App Engine exploits three weeks after private reports went unanswered, and Google later disclosed an unpatched Edge flaw months after private reporting. What changed is that Google now treats confirmed in-the-wild exploitation as grounds to override the negotiated timeline entirely.
First-order effects
- Windows users are exposed to a publicly documented, actively exploited flaw with no patch from Microsoft, turning every attacker with the write-up into a potential operator.
- Microsoft faces immediate pressure to ship an out-of-band fix rather than wait for its regular Patch Tuesday cycle, since silence now reads as confirmation the bug is live.
Second-order effects
- Every vendor in Google's crosshairs must now plan for a disclosure clock measured in days, not weeks, whenever exploitation is claimed — the App Engine and Edge episodes show even Google accepts this standard being applied to itself.
- Rival platform owners gain a reputational lever: each forced early disclosure becomes evidence in the ongoing argument over whose ecosystem patches faster.
Third-order effects
- If the pattern holds, coordinated disclosure hardens into a two-tier norm — a generous private window for ordinary bugs, near-immediate publication once exploitation is verified — shifting real power to whichever researcher controls the proof-of-exploit.
- Patch infrastructure built around monthly cycles becomes a structural liability; vendors unable to respond inside an exploitation-driven window will increasingly see their flaws disclosed unpatched, as Microsoft did in 2015 and again here.
The trend: Vulnerability disclosure timelines are compressing from Project Zero's original 90-day deadline toward a days-long standard whenever a flaw is confirmed exploited in the wild.