Google's Project Zero says 95.8% of the 1,585 security flaws it reported since July 2014 were fixed before its 90-day deadline for a public disclosure
Context & Ripple Effects
This stat sheet lands midway through Project Zero's decade-long argument with the software industry over disclosure deadlines. The team made its name by publishing unpatched bugs — including posting a Windows 8.1 flaw after Microsoft missed the 90-day window — then softened the edge with a 14-day grace period for vendors actively working on fixes.
The 95.8% figure is effectively the scoreboard for that regime: most vendors now patch inside the window rather than forcing public disclosure. It also frames the policy tweaks that followed — a 2020 trial disclosing all bugs at day 90 regardless of fix status, and a 2021 update adding a 30-day cushion so users can apply patches before details go public.
First-order effects
- The deadline is doing its job on the vendors it was aimed at: per Project Zero's own data, Microsoft averages 83 days to patch and Apple 69 — both cutting it close to the 90-day line where publication forces their hand.
- The small share disclosed unpatched means far fewer vendors now experience the public-shaming route that defined Project Zero's early years.
Second-order effects
- Patch speed is becoming a comparable metric across platforms — Linux's 25-day average against Google's own 44 gives buyers and enterprises a way to rank vendor security responsiveness, not just feature sets.
- Each round of vendor pushback has produced policy concessions — the grace period, then the user-facing cushion — meaning the disclosure process itself is being negotiated rather than imposed one-way by Google.
Third-order effects
- If the pattern holds, deadline-driven coordinated disclosure becomes the industry default rather than Google's idiosyncratic stance, with the open question being whether other research teams adopt the same published clocks or whether vendors face fragmented standards from competing bug-reporting regimes.
The trend: Software vulnerability handling is consolidating around hard disclosure deadlines, turning time-to-patch into a publicly tracked performance metric for major platform vendors.