Earlier quoted context omitted.
I really dislike your description because while it is technically true it heavily implies that they decided on dates on a per-bug case, when they decided on a flat 90 days.
Then again, 90 days contains 2.5 of their fix cycles. If the vulnerability really is serious, and they can't fix it in that time line, they should exit the business.
Microsoft supports all versions of all their products for 10years+ after release, integrated with a combination of all other products they have shipped in that same time-frame.
Needless to say, Microsoft needs to do more QA on their bug-fixes before they can safely release it to all customers without the risk of causing new issues.
It's easy for Google to be big in the mouth when they don't bother to support their existing customers properly.
Speaking of being big in the mouth: Did you know that Google isn't back-porting security fixes to older versions of Android either (only 2 last minor releases)? I guess supporting more than 40% of your user base is too much work.
Guess which side my sympathy is leaning to in this case.