Assessment of the responsiveness in addressing vulnerabilities discovered by Google Project Zero

Researchers from the Google Project Zero team summarized data on the response times of manufacturers to newly discovered vulnerabilities in their products. According to Google's policy, manufacturers have 90 days to address vulnerabilities identified by Google Project Zero researchers, with an additional public disclosure potentially delayed by another 14 days upon separate request. After 104 days, details about the vulnerability are disclosed even if the issue remains unresolved.

From 2019 to 2021, the project identified 376 issues, of which 351 (93.4%) were fixed. 11 vulnerabilities (2.9%) remained unfixed, and another 14 (3.7%) issues were marked as Won't Fix. Over the years, there has been a decrease in the number of vulnerabilities for which fixes are not completed within the allocated time frame — in 2021, an additional 14 days were requested for 14% of vulnerabilities, and only one issue remained unfixed by the time of disclosure.

Manufacturer

Number of Issues

Fixed within 90 days

Fixed within additional 14 days

Not fixed within the allocated time

Average number of days to fix

Apple

84

73 (87%)

7 (8%)

4 (5%)

69

by Microsoft

80

61 (76%)

15 (19%)

4 (5%)

83

Google

56

53 (95%)

2 (4%)

1 (2%)

44

Linux

25

24 (96%)

0 (0%)

1 (4%)

25

Adobe

19

15 (79%)

4 (21%)

0 (0%)

65

Mozilla

10

9 (90%)

1 (10%)

0 (0%)

46

Samsung

10

8 (80%)

2 (20%)

0 (0%)

72

Oracle

7

3 (43%)

0 (0%)

4 (57%)

109

Others*

55

48 (87%)

3 (5%)

4 (7%)

44

TOTAL

346

294 (84%)

34 (10%)

18 (5%)

61

On average, it took 52 days to create a vulnerability fix in 2021, 54 days in 2020, 67 days in 2019, and 80 days in 2018. Vulnerabilities were addressed most quickly in the Linux kernel — averaging 15, 22, and 32 days in 2021, 2020, and 2019, respectively. Microsoft took the longest to issue fixes, averaging 76, 87, and 85 days (Oracle was even slower, with an average of 109 days). Apple averaged 64, 63, and 71 days to fix their vulnerabilities. In Google products, the average time to generate fixes over the years was 53, 22, and 49 days.

Vendor

Bugs in 2019

(avg days to fix)

Bugs in 2020

(avg days to fix)

Bugs in 2021

(avg days to fix)

Apple

61 (71)

13 (63)

11 (64)

by Microsoft

46 (85)

18 (87)

16 (76)

Google

26 (49)

13 (22)

17 (53)

Linux

12 (32)

8 (22)

5 (15)

Others*

54 (63)

35 (54)

14 (29)

TOTAL

199 (67)

87 (54)

63 (52)

Among browser manufacturers, Chrome has the most timely fixes, yet Firefox releases patches faster after the fix appears (in Chrome and Safari, vulnerabilities fixed in code remain unaddressed for users for a significant period, which is exploited by attackers).

Browser Number of IssuesAverage days from notification of the issue to patch publicationAverage time from patch publication to product releaseAverage time from vulnerability notification to release with fix

Activated

40

5.3

24.6

29.9

WebKit

27

11.6

61.1

72.7

Firefox

8

16.6

21.1

37.8

Total

75

8.8

37.3

46.1



Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster