Depends on the flaw, might give them long enough to make a fix [1] (they might have one in the pipeline, or one they kept from release because of effects on speed, you never know) but more than likely gives them long enough to decide _how_ to handle it.
[1] I'm partially recalling a fix, on Facebook I think, that was implemented within a few hours of reporting; it was ac testing API that got exposed. Different field, of course.
[1] I'm partially recalling a fix, on Facebook I think, that was implemented within a few hours of reporting; it was ac testing API that got exposed. Different field, of course.