Hi Alex, Yes, 9 July sounds good to me. No problem if it slips to a different day though: just let me know and I will delay my announcement too. (The 90 day deadline is really only there for when we're dealing with an irresponsible vendor who cannot be bothered to fix something.) I hope you don't mind that I am planning to write a blog post about the bug (something similar to https://lgtm.com/blog/facebook_fizz_CVE-2019-3560). The blog post won't describe the exact details of the exploit though. I usually wait around 1 month before posting the exploit code on https://github.com/Semmle/SecurityExploits. Thanks, Kev On Thu, Jun 13, 2019 at 1:41 PM Alex Murray