/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google discloses security flaw of “medium” severity in Microsoft Edge after privately reporting the flaw to Microsoft in November 2017; no patch available yet

Usama Jawad / Neowin :

Neowin Usama Jawad

Context & Ripple Effects

This is now a repeating pattern rather than a one-off: almost exactly a year earlier, Google disclosed a high-severity type-confusion bug in IE 11 and Edge on the same terms — private report in November, public post with no patch available (high-severity type-confusion bug in IE 11 and Edge). The practice traces back further still, to Project Zero posting a Windows 8.1 flaw in January 2015 after Microsoft missed the 90-day deadline (Project Zero posted a Windows 8.1 flaw).

What makes today's disclosure notable is its restraint by comparison: a 'medium' severity rating and a full private-reporting window before publication, versus the actively exploited Windows vulnerability Google published just ten days after reporting in 2016 (disclosed an actively exploited Windows vulnerability after only ten days). The severity label and elapsed time are doing the work of signaling how Google calibrates pressure.

First-order effects

  • Microsoft faces public pressure to ship an Edge fix for a flaw it has known about since November 2017, while Edge users remain exposed to an unpatched medium-severity bug in the interim.
  • Google's disclosure puts the state of Microsoft's patch pipeline on the record — the absence of a fix roughly three months after the private report is itself the story.

Second-order effects

  • Every subsequent Google disclosure against Microsoft now lands against this track record, forcing Microsoft to either accelerate Edge patch turnaround or absorb recurring public deadline misses.
  • The severity downgrade from last year's 'high' to this year's 'medium' gives Microsoft room to deprioritize without the same reputational cost — but also lets Google demonstrate its policy scales pressure to risk rather than applying it uniformly.

Third-order effects

  • If the pattern holds across the 2015, 2016, 2017, and 2018 disclosures, fixed vendor deadlines become the de facto industry norm for cross-company bug reporting, with the disclosing vendor — not the affected one — controlling the clock.
  • Browser vendors' security practices turn into a competitive signal: Google can patch Chrome on its own schedule (as with its later zero-day fixes) while publishing rivals' lag, converting its research arm into a standing advantage.

The trend: Cross-vendor vulnerability disclosure is hardening into a deadline-driven regime where Google's Project Zero sets the clock and vendors like Microsoft must restructure their patch pipelines around it.