Yeah, says Google Project Zero, when you think about it, going public with exploit deets immediately after a patch is emitted isn't such a great idea

At least this makes malware authors work harder.

There is no upside for full disclosure at the same time as patch release, so waiting the full 90 days makes sense even if some more clueful malware writers might disassemble the code and reverse engineer the bug before that time.

