Google's Project Zero tracks vulnerabilities in software systems and reports them to vendors "in as close to real-time as possible"— a noble cause, no? But what happens if said vendor then fails to push a fix within the 90-day window?
↧