Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google Project Zero’s July 29, 2025 Reporting Transparency trial adds an early public notice to its existing vulnerability-disclosure process. The notice is intended to identify the recipient and affected product, give the report date, and show when the 90-day deadline expires—but it does not reveal technical details or shorten the time vendors have to fix the issue.

What changed in Project Zero’s disclosure policy?

Project Zero said it would aim to publish an early signal within approximately one week after reporting a vulnerability to a vendor or open-source project. The announcement describes this as a trial, not a replacement for the established disclosure timeline. Project Zero’s July 29, 2025 announcement says Google Big Sleep—a collaboration between Google DeepMind and Project Zero—will also trial the policy for its vulnerability reports.

The early notice is designed to state who received the report, which product is affected, when the report was filed, and when the 90-day disclosure deadline expires. This gives downstream organizations a lead to investigate whether an upstream issue could affect their own products.

How the early notice differs from technical disclosure

Stage Timing What becomes public Practical purpose
Early transparency notice Project Zero aims for approximately one week after the report is sent. Recipient, affected product, report date, and 90-day deadline. Alert downstream dependents so they can assess possible exposure and coordinate with suppliers.
Technical disclosure At the ordinary deadline, subject to the stated 90+30 framework. Technical details may be disclosed; the early notice itself does not provide them. Allow the issue to be understood and addressed after the disclosure period.

Project Zero says it will withhold technical details, proof-of-concept code, and information it believes would materially help someone discover the vulnerability before the deadline. As the announcement puts it: “Reporting Transparency is an alert, not a blueprint for attackers.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

How long does a vendor have to fix a Project Zero bug?

The July 2025 announcement says the existing 90+30 model remains in effect. A vendor has 90 days to fix the reported issue before disclosure. If it fixes the issue before the 90-day deadline, the framework includes a further 30 days for patch adoption. The new notice is an additional early signal; it does not start a shorter embargo or bring forward the technical disclosure deadline.

Project Zero’s 2015 policy post described a different historical arrangement: a 90-day deadline and a 14-day grace period when a vendor confirmed a specific patch date within that period. That earlier rule should not be confused with the 90+30 framework stated in the 2025 announcement. Project Zero’s 2015 policy post also reported that Adobe Flash had fixed 37 Project Zero vulnerabilities, described as 100% of those researched at that point; 154 bugs had been fixed by the time of the post, with 85% fixed within 90 days; and, among 73 issues filed and fixed after October 1, 2014, 95% were fixed within 90 days. These are historical figures, not evidence about the new trial.

Why Project Zero wants to notify downstream organizations

Project Zero calls the delay between an upstream fix and its integration into products used by customers the “upstream patch gap.” A supplier may have a fix ready while organizations and vendors that depend on its software have not yet incorporated it. Project Zero’s stated expectation is that an early signal can help those downstream groups identify potentially affected products and coordinate with their suppliers.

The notice may also draw attention to bugs that remain unfixed. Project Zero acknowledges that risk, while arguing that early awareness can help defenders and downstream dependents. It says the added noise may be unwelcome for vendors without a downstream ecosystem, but characterizes those vendors as a minority of its reports; that is Project Zero’s assessment, not independently established market data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the historical metrics do—and do not—show

In a separate analysis published in 2022, Project Zero examined 376 issues reported to vendors under the standard 90-day deadline between 2019 and 2021. It said 351 issues (93.4%) were fixed, 14 (3.7%) were marked WontFix, and 11 (2.9%) remained unfixed at the time of analysis. The post reported an average 52 days to fix in 2021, compared with about 80 days three years earlier. Project Zero’s 2022 metrics post cautioned that its reports may be outliers because of the team’s trusted status and the tangible risk of public disclosure.

Those numbers describe an earlier period and the standard reporting process, not the effect of Reporting Transparency. The July 2025 announcement presents the policy as a trial whose effects will be monitored; it does not provide results showing that early notices have reduced patch delays.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.