Google Project Zero Adds Early Disclosure Step to Speed Up Security Patches
Google Project Zero has announced a trial update to its long standing vulnerability disclosure policy, known as the 90+30 model. Under this model, vendors are given 90 days to fix a reported security flaw, with an additional 30 days for users to install the patch before details are made public. While this approach has improved patch development speed, Project Zero says a hidden delay still slows things down: the 'upstream patch gap'. This occurs when a foundational technology provider, such as a chipset or driver maker, releases a fix, but the companies that build products using that technology have not yet incorporated it.
To address this, Project Zero will now publicly disclose that a vulnerability has been reported to a vendor within about one week of the report, rather than waiting until the end of the 90 day window. The original 90+30 disclosure timeline remains unchanged; this is simply an added early signal. Google Big Sleep, a joint project between Google DeepMind and Project Zero, will also test this new transparency approach for its own vulnerability reports.
The goal is to give downstream vendors and businesses that rely on affected technology earlier warning that a fix is coming, so they can prepare to update their products sooner rather than only learning about issues once they are already public.