Project Zero aims to push companies to patch software security vulnerabilities before they become a threat, but that effort hasn't been very successful.
As Apple and Microsoft point out, the strict 90-day notification deadline sometimes leaves developers scrambling to finish patches that need to be released after an exploit is discovered. Fortunately, Google seems to be listening to these complaints, and the Project Zero team has changed its policies to give developers more time to create patches. Companies now have a 14-day “grace period” to release security updates if Google is notified that the code won’t be ready within the usual 90-day timeframe. Also, Mountain View employees won’t ruin employees’ days off by disclosing vulnerabilities during holidays and weekends.
Project Zero's policy is still not as lenient with others as ZDI's 120-day program. Even so, it could go a long way toward bridging the gap between Google's ideals and the practical problems of delivering security updates consistently. Unless security developers show significant lag, there's little chance that a virus's creators will get a head start and attack your devices before you can protect yourself.

