Google Reveals 2 More Windows Bugs After Microsoft's Public Criticism

Advertisement
By Hitesh Arora | Updated: 19 January 2015 14:23 IST
After publicly criticising Google's decision to disclose a vulnerability in Windows 8.1 two days before Microsoft planned to issue the fix, it was expected that the two company will resolve further issues behind curtains. But last week, Google again went ahead and disclosed two more bugs of Windows 7 and Windows 8.1 to public as per its Project Zero policy.

Out of the two bugs was reported to Microsoft on October 17 last year, the first allows Windows 7 and Windows 8.1 attackers to impersonate a normal user at identification level and decrypt or encrypt data for a logon session, and the second allows Windows 7 attackers to see power settings information only.

Commenting on the impersonation and logon bug, a Project Zero member noted on Wednesday, "Asked Microsoft for information on whether they were going to fix this issue and timescales of it. Notified them that the current deadline is the 15th January."

"Microsoft informed us that a fix was planned for the January patches but has to be pulled due to compatibility issues. Therefore the fix is now expected in the February patches," added project member on the forum.

Advertisement

For the power settings information bug, both companies have agreed to the issue not being that much of a problem, so no patch has been planned as yet, though it will remain under consideration, noted Google's forum, "Microsoft have stated that this issue is not considered serious enough for a bulletin release as it only allows limited information disclosure about power settings. It will be under consideration for fixing in future versions of Windows. We agree with this assessment and will remove the view restriction on the issue.

Advertisement

To remind you, Microsoft's Senior Director of the Microsoft Security Response Center, Chris Betz, had published an official blog post last week, criticising Google's irresponsible action of disclosing a 90-day-old bug before the company not only planned a fix for the problem on January 13, but also asked Google not to go public until that day.

Advertisement

But for Google, the disclosure was made as a part of its Project Zero security initiative that stipulates a 90-day deadline for the fix before the public disclosure of the bug.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  4. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  5. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  6. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  7. Nothing Phone 3a Lite Goes on Sale in India at This Price
  8. Vivo S50 Colour Options, Key Features Surface Online Ahead of Launch
  9. OTT Releases of the Week (Dec 1 – Dec 7): Know What to Watch
  10. Realme 16 Pro+ 5G New Leak Reveals Storage and Colour Variants
  1. Motorola Edge 70 India Launch Teased; Flipkart Availability Confirmed: Expected Specifications, Features
  2. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  3. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  4. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  5. Realme 16 Pro+ 5G Colour Options, Memory Configurations Leaked Again; Tipped to Launch With 7,000mAh Battery
  6. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  7. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  8. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  9. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  10. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.