The 90-Day Disclosure Policy Is Dead. Long Live... What?
Google kills the rigid 90-day bug disclosure deadline, opting for flexibility. Developers, don't celebrate just yet.

Remember when security researchers would give you exactly three months to patch a vulnerability before going public? Google just pulled the plug on that era. The 90-day deadline is officially dead, replaced by a more flexible, case-by-case approach. It's like your boss saying "deadlines are now suggestions" — sounds great, but also terrifying.
What's changing?
Google's Project Zero, the elite bug-hunting squad, announced they're ditching the strict 90-day disclosure policy. Instead, they'll negotiate timelines with vendors, considering the complexity of the fix and the risk to users. No more countdown clocks, no more public shaming on day 91.
Why does this matter? The old policy was a double-edged sword: it pressured vendors to patch quickly, but sometimes left users exposed when a fix wasn't ready. Google says the new approach aims for "responsible disclosure" — basically, they'll work with you instead of against you.
Of course, not everyone is cheering. Critics argue that without a hard deadline, vendors will drag their feet even more, pushing fixes to the mythical "next sprint" (you know the one). Researchers worry their reports will gather dust in JIRA for months. And let's be honest: we've all seen how "flexible deadlines" work in practice — spoiler: they stretch.
METABYTE's take: We're all for collaboration, but remember: if your codebase is a tangled mess, no amount of negotiation will save you. Write clean code, test early, and you won't need to fear any disclosure policy — 90 days or not.
NEXT STEP
Liked the approach?
We apply the same principles to client projects: AI, automation, products that don't die after launch.