Even though it's part of the original post's title, "please do not make it public" is an extremely misleading quote.
> Vulnerability disclosed to IMETS@tencent.com.
> Vulnerability disclosed again via Tencent Security Response Centre (TSRC) web portal.
> Tencent: “Thank you for your interest in Tencent security. There is no low or low security risk for this issue. We look forward to your next more exciting report.”
> Tencent: “Sorry, my previous reply was wrong, we are dealing with this vulnerability, please do not make it public, thank you very much for your report.”
> Tencent’s initial rejection of our disclosure and subsequent about-face served as inspiration for the title of this report.
It's a direct quote from a Tencent reply.