Blog | G5 Cyber Security

Policy and Disclosure: 2020 Edition

Project Zero is changing its vulnerability disclosure policy for January 1, 2020. Full 90 days by default, regardless of when the bug is fixed, will be released on the day it is fixed. The seven day deadline for vulnerabilities that are being actively exploited “in the wild” will remain unchanged. Inconsistent handling of incomplete fixes will be reported to the vendor and added to the existing report (which may already be public) and will not receive a new deadline. If a vendor wants to synchronize the opening of our tracker report with their release notes to minimize user confusion and questions. The current list of changes for 2020:”]

Source: https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html

Exit mobile version