In the process of disclosing security vulnerabilities, researchers generally follow the CVD model, which aims to give vendors ample time to prepare fixes or mitigations, thereby minimizing the impact of the vulnerability as quickly as possible. This approach involves researchers immediately reporting vulnerability details to vendors, and then, after 90 days or upon the release of a security patch, disclosing the vulnerability and its mitigation measures to the public. The timely disclosure of vulnerabilities by researchers, swift vendor responses, and prompt updates for users are all crucial in mitigating the damage caused by such vulnerabilities.