....did Google just admit to patching a security hole and not announcing it for months? Isn't this what they continuously harangue other organizations for on Google's Project Zero blog?
Yep: https://www.nbcnews.com/tech/tech-news/google-says-it-found-...
"As many as 438 applications might have used the API. Google maintains that it didn’t uncover evidence developers were aware of or abused the security flaw, or that profile data was misused. However, it acknowledged that it has no way of knowing for sure because it doesn’t have “audit rights” over its developers and because it keeps a limited set of activity logs." (https://venturebeat.com/2018/10/08/google-security-breach/)
Google wrote: “Our Privacy & Data Protection Office reviewed this issue, looking at the type of data involved, whether we could accurately identify the users to inform, whether there was any evidence of misuse, and whether there were any actions a developer or user could take in response. None of these thresholds were met in this instance.”
--
From 2016: "The search engine company publicised a critical Windows bug 10 days after informing the software firm about it" (https://www.theguardian.com/technology/2016/nov/01/google-mi...)
From February: "Microsoft misses Google's 90-day deadline, so Google has published details of an exploit mitigation bypass" (https://www.zdnet.com/article/windows-10-security-google-exp...)
And then: "For the second time in a week, Google reveals another unpatched Windows 10 vulnerability" (https://www.zdnet.com/article/windows-10-bug-google-again-re...)
In August: "Google discloses vulnerability in Fortnite launcher that allowed possible malware installation" (https://www.gamesindustry.biz/articles/2018-08-27-google-dis...)
Again in August, reporting Samsung bugs: (https://www.zdnet.com/article/google-project-zero-heres-the-...):
"Two terms irked her and simply clashed with Project Zero's practices. "You MUST hold off disclosing the vulnerability in reasonable time, and you MUST get Samsung's consent or inform Samsung about the date before disclosing the vulnerability," said Samsung. "In some cases, Samsung may request not to disclose the vulnerability at all." Again, this clashes with Project Zero's insistence on disclosure."