A walk through Project Zero metrics
Google's Project Zero blog looksat how quickly the vulnerabilities it has reported over the last three years have been fixed.
From this, we can see a few things: first of all, the overall timeto fix has consistently been decreasing, but most significantlybetween 2019 and 2020. Microsoft, Apple, and Linux overall havereduced their time to fix during the period, whereas Google sped upin 2020 before slowing down again in 2021. Perhaps mostimpressively, the others not represented on the chart havecollectively cut their time to fix in more than half, though it'spossible this represents a change in research targets rather than achange in practices for any particular vendor.
The report also says that Linux vulnerabilities were fixed more quicklythan any other.