A bit of context...

"Google found the flaw, told epic, gave them 7 days to sort their ..."

To put a bit of context on this: in December 2008, a group of researchers found a collision attack on MD5 hashing that undermined SSL certificates in use at the time - in this case, a one week responsible disclosure period was applied.

So I guess either Google rate this threat as highly as the compromise of every web browser out there, or this is just sour grapes... and it's not like Google haven't got form for pulling the trigger on disclosure when it suits them as opposed to when is responsible...

