Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Security experts weigh in on Microsoft-Google security vulnerability disclosure

Security experts weigh in on Microsoft-Google security vulnerability disclosure

Dave W. Shanahan Dave W. Shanahan
August 23, 2019
2 min read

Security experts weigh in on Microsoft-Google security vulnerability disclosure

In December, WinBeta reported on Microsoft bug found by a Google researched named “forshaw.” Yesterday, the first Patch Tuesday of 2015, Microsoft released a patch fixing the security flaw. Microsoft has since blamed Google for the negligent and unprofessional disclosure. Google countered that it originally shared the information with Microsoft on October 13, 2014 giving a strict 90-day disclosure policy. Microsoft asked Google not to release details about the issue until a fix was released. After the 90 days were up, Google shared the details of the bug publicly before Microsoft created a fix.

It is unclear whether Google or Microsoft are to blame for this clear failure of communication, but hopefully there is a way companies can deal with these problems quietly without releasing this kind of information publicly. Michael Taylor, lead developer at Rook Securities, gave his opinion:

Google provided Microsoft ample time to identify and create a suitable patch for this issue. Microsoft had two full patch cycles to address this vulnerability before Google disclosed it publicly. The question is why Microsoft was unable or unwilling to address these vulnerabilities in a timely manner.

I do not know which company is right or wrong, but I think there should be a better system in place for sharing this sort of private information. Surely, Google would not want such a security flaw publicly exposed on their Android OS. Researchers want to know that vendors take their vulnerability discoveries seriously and maybe the Google leak was the researchers’ way of getting the attention that they deserve.   

I feel like Google gave Microsoft adequate time to create a patch for the security flaw. Microsoft seems heated that the information was shared publicly; allowing the flaw to be exploited. I think Google releasing the security vulnerability, with the code to exploit the vulnerability is irresponsible. I think Google should have taken more steps in contacting Microsoft about the security flaw, regardless if the companies are competitors or not. 

Your thoughts?

Further reading: Google, Microsoft, Windows

Share this article:
Tags:
Google Microsoft Windows
Previous Article Stream content on Netflix via HTML5 thanks to Internet Explorer 11 Next Article Better hurry! Microsoft is offering a free Lumia 520 with select AT&T phones

Related Articles

Chrome and Gemini icons representing Gemini Live voice assistant integration in Chrome

Chrome tests Gemini Live voice assistant in a floating overlay panel

March 14, 2026

Chrome’s Organizer feature may sync Gemini and AI conversations across devices

March 14, 2026

After Chrome, Edge tests launching the browser automatically when you sign into Windows

March 13, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy