/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google's Project Zero says 95.8% of the 1,585 security flaws it reported since July 2014 were fixed before its 90-day deadline for a public disclosure

Catalin Cimpanu / ZDNet :

ZDNet Catalin Cimpanu

Context & Ripple Effects

This stat sheet lands midway through Project Zero's decade-long argument with the software industry over disclosure deadlines. The team made its name by publishing unpatched bugs — including posting a Windows 8.1 flaw after Microsoft missed the 90-day window — then softened the edge with a 14-day grace period for vendors actively working on fixes.

The 95.8% figure is effectively the scoreboard for that regime: most vendors now patch inside the window rather than forcing public disclosure. It also frames the policy tweaks that followed — a 2020 trial disclosing all bugs at day 90 regardless of fix status, and a 2021 update adding a 30-day cushion so users can apply patches before details go public.

First-order effects

  • The deadline is doing its job on the vendors it was aimed at: per Project Zero's own data, Microsoft averages 83 days to patch and Apple 69 — both cutting it close to the 90-day line where publication forces their hand.
  • The small share disclosed unpatched means far fewer vendors now experience the public-shaming route that defined Project Zero's early years.

Second-order effects

  • Patch speed is becoming a comparable metric across platforms — Linux's 25-day average against Google's own 44 gives buyers and enterprises a way to rank vendor security responsiveness, not just feature sets.
  • Each round of vendor pushback has produced policy concessions — the grace period, then the user-facing cushion — meaning the disclosure process itself is being negotiated rather than imposed one-way by Google.

Third-order effects

  • If the pattern holds, deadline-driven coordinated disclosure becomes the industry default rather than Google's idiosyncratic stance, with the open question being whether other research teams adopt the same published clocks or whether vendors face fragmented standards from competing bug-reporting regimes.

The trend: Software vulnerability handling is consolidating around hard disclosure deadlines, turning time-to-patch into a publicly tracked performance metric for major platform vendors.

Discussion

  • @nchlgpt Aanchal Gupta on x
    Just adding two weeks of grace period has upped the fix rate by 14% by allowing vendors to keep their patch rollout schedule. https://www.zdnet.com/...
  • @campuscodi Catalin Cimpanu on x
    Google Project Zero: 95.8% of all bug reports are fixed before deadline expires. GP0 researchers said that since July 2014 they found and reported 1,585 vulnerabilities, of which only 66 passed their deadline and were made public without a fix. https://www.zdnet.com/... https://t…