Microsoft kicked off a new program on Tuesday, responsible for the discovery, reporting, and coordination of vulnerabilities in third-party products and services.
The Microsoft Vulnerability Research (MSVR) program launched on Tuesday with two Google Chrome vulnerabilities. Microsoft has a mixed history with Google over responsible vulnerability disclosure after Google’s senior security researcher, Tavis Ormandy, notified Microsoft about two flaws at the beginning of June then days later Ormandy published proof of concept code, saying “without a working exploit, I would have been ignored.” The working exploit saw attacks increase rapidly and Microsoft claimed the Google workers move put customers at risk.
Full Story:
Microsoft’s new vulnerability disclosure policy kicks off with two Chrome flaws | WinRumors