guys this is the same like google and microsoft...
google finds the vulnerability/bug and tells microsoft about it.
after few months or year (i dont remember) they will start to make it public and then microsoft start to fix it xD
soooo i think its ok x)