Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Security experts weigh in on Microsoft-Google security vulnerability disclosure

Security experts weigh in on Microsoft-Google security vulnerability disclosure

Dave W. Shanahan Dave W. Shanahan
August 23, 2019
2 min read

Security experts weigh in on Microsoft-Google security vulnerability disclosure

In December, WinBeta reported on Microsoft bug found by a Google researched named “forshaw.” Yesterday, the first Patch Tuesday of 2015, Microsoft released a patch fixing the security flaw. Microsoft has since blamed Google for the negligent and unprofessional disclosure. Google countered that it originally shared the information with Microsoft on October 13, 2014 giving a strict 90-day disclosure policy. Microsoft asked Google not to release details about the issue until a fix was released. After the 90 days were up, Google shared the details of the bug publicly before Microsoft created a fix.

It is unclear whether Google or Microsoft are to blame for this clear failure of communication, but hopefully there is a way companies can deal with these problems quietly without releasing this kind of information publicly. Michael Taylor, lead developer at Rook Securities, gave his opinion:

Google provided Microsoft ample time to identify and create a suitable patch for this issue. Microsoft had two full patch cycles to address this vulnerability before Google disclosed it publicly. The question is why Microsoft was unable or unwilling to address these vulnerabilities in a timely manner.

I do not know which company is right or wrong, but I think there should be a better system in place for sharing this sort of private information. Surely, Google would not want such a security flaw publicly exposed on their Android OS. Researchers want to know that vendors take their vulnerability discoveries seriously and maybe the Google leak was the researchers’ way of getting the attention that they deserve.   

I feel like Google gave Microsoft adequate time to create a patch for the security flaw. Microsoft seems heated that the information was shared publicly; allowing the flaw to be exploited. I think Google releasing the security vulnerability, with the code to exploit the vulnerability is irresponsible. I think Google should have taken more steps in contacting Microsoft about the security flaw, regardless if the companies are competitors or not. 

Your thoughts?

Further reading: Google, Microsoft, Windows

Share this article:
Tags:
Google Microsoft Windows
Previous Article Stream content on Netflix via HTML5 thanks to Internet Explorer 11 Next Article Better hurry! Microsoft is offering a free Lumia 520 with select AT&T phones

Related Articles

Intel Panther Lake laptops see major price hikes due to component shortages, while Apple MacBook M5 models continue with unchanged pricing globally.

Intel Laptop Price Increase Hits Panther Lake Models, Apple MacBook M5 Stays Stable

April 5, 2026
State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op

State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op

April 5, 2026
Starfield launches on PS5 with 4K visual mode, 60FPS performance option, DualSense features, and new DLC available at release for players

Starfield Launches on PS5 With Two Modes and Full DualSense Support

April 5, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Intel Laptop Price Increase Hits Panther Lake Models, Apple MacBook M5 Stays Stable
  • State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op
  • Starfield Launches on PS5 With Two Modes and Full DualSense Support
  • ASUS Accused of Failing to Fix Laptop After 10 RMAs, User Denied 11th Request
  • New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Intel Laptop Price Increase Hits Panther Lake Models, Apple MacBook M5 Stays Stable
  • State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op
  • Starfield Launches on PS5 With Two Modes and Full DualSense Support
  • ASUS Accused of Failing to Fix Laptop After 10 RMAs, User Denied 11th Request
  • New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy