But I find that this case is rare. Typically it would be something like many of the following being met:
- It is likely to be discovered by an attacker soon.
- History shows that the company is unlikely to fix it soon.
- Users have some way to protect themselves.
- Your disclosure is likely to reach a significant number of users.