So is the argument that Google should leave the vulnerability unpatched in its own browser until Adobe get around to patching it in their plugin for other browsers, so as not to publicize the existence of a vulnerability? What if they have detected black hats exploiting the vulnerability. Should they sit on a fix? What if they were building their own implementation of a programming language or tool. For example, what…
If you find out a vulnerability is being exploited in the wild, and already have a patch or technical description, you should release it. If one of the two parts commits a mistake and releases information about the vulnerability (like, for example, a patch that can be reverse-engineered), then all other involved parts should release what they have.
If they don't have a patch or if they aren't ready to release it, which seems to be the case here, Adobe should at least release technical details. These can be used to mitigate the impact of the vulnerability on unpatched hosts.