Cybersecurity Research

Google's Project Zero Updates Vulnerability Disclosure Policy for 2025

Project Zero · 30 July 2025
Key Takeaway Keep all software and systems set to auto-update, since faster patching is your best defence regardless of how disclosure timelines change.

Google's Project Zero, one of the world's most influential cybersecurity research teams, has published an updated version of its vulnerability disclosure policy for 2025. Project Zero is known for hunting down serious security flaws in widely used software and working with vendors to get them fixed before attackers can exploit them.

Disclosure policies like this one set the rules for how long vendors have to patch a discovered vulnerability before details are made public, balancing the need to give companies time to fix problems against the risk of flaws sitting unpatched indefinitely. Because so much of the software ecosystem relies on the same underlying platforms, browsers, and operating systems, changes to how a group like Project Zero handles disclosure can influence patch timelines across the industry, including software used by small businesses.

While the full technical details of the update were not specified, policy changes from a research team of this influence are worth tracking, as they can affect how quickly critical patches become available and how much warning businesses get before vulnerability details go public.

Summarised by CISO AI from Project Zero. We link back to every original so you can read it yourself.