← Back to context

Comment by progval

16 hours ago

They don't have to publish a working exploit as soon as the embargo is broken, though.

Perhaps, but if the exploit code is published folks can double-check that they implemented the mitigations properly.

If there's no PoC, how can you really be sure?

anyone who will use the exploit maliciously will immediately and trivially be able to create a working exploit.

Why not? There has already been a working exploit floating around, at least now it comes from an authoritative source.