#Microsoft says:
Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences
Lucky for us, those vulns just occur spontaneously in nature. It would be awful if a company brought the unpatched vulnerabilities to market and sold them at a profit with no liability for doing so.
More to the point, it is a very debatable position that companies like Microsoft should have no accountability (warranty, liability, whatever) no matter how bad their released software is. Microsoft omits how the law treats them so specially.
Microsoft wants the exploit maker held accountable. Microsoft is very interested in seeing the law applied to HIM. Laws holding THEM accountable for vulns? Suddenly theyโre not as interested.
Heisenbergโs importance. Windows occupies two simultaneous states: so important that we mustโt recklessly disclose vulns, but not important enough to regulate for the good of society.
https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085