Google discloses security flaw of “medium” severity in Microsoft Edge after privately reporting the flaw to Microsoft in November 2017; no patch available yet
Context & Ripple Effects
This is now a repeating pattern rather than a one-off: almost exactly a year earlier, Google disclosed a high-severity type-confusion bug in IE 11 and Edge on the same terms — private report in November, public post with no patch available (high-severity type-confusion bug in IE 11 and Edge). The practice traces back further still, to Project Zero posting a Windows 8.1 flaw in January 2015 after Microsoft missed the 90-day deadline (Project Zero posted a Windows 8.1 flaw).
What makes today's disclosure notable is its restraint by comparison: a 'medium' severity rating and a full private-reporting window before publication, versus the actively exploited Windows vulnerability Google published just ten days after reporting in 2016 (disclosed an actively exploited Windows vulnerability after only ten days). The severity label and elapsed time are doing the work of signaling how Google calibrates pressure.
First-order effects
- Microsoft faces public pressure to ship an Edge fix for a flaw it has known about since November 2017, while Edge users remain exposed to an unpatched medium-severity bug in the interim.
- Google's disclosure puts the state of Microsoft's patch pipeline on the record — the absence of a fix roughly three months after the private report is itself the story.
Second-order effects
- Every subsequent Google disclosure against Microsoft now lands against this track record, forcing Microsoft to either accelerate Edge patch turnaround or absorb recurring public deadline misses.
- The severity downgrade from last year's 'high' to this year's 'medium' gives Microsoft room to deprioritize without the same reputational cost — but also lets Google demonstrate its policy scales pressure to risk rather than applying it uniformly.
Third-order effects
- If the pattern holds across the 2015, 2016, 2017, and 2018 disclosures, fixed vendor deadlines become the de facto industry norm for cross-company bug reporting, with the disclosing vendor — not the affected one — controlling the clock.
- Browser vendors' security practices turn into a competitive signal: Google can patch Chrome on its own schedule (as with its later zero-day fixes) while publishing rivals' lag, converting its research arm into a standing advantage.
The trend: Cross-vendor vulnerability disclosure is hardening into a deadline-driven regime where Google's Project Zero sets the clock and vendors like Microsoft must restructure their patch pipelines around it.