"Ormandy's finding prompted the Slovak company to rush a patch a day before his disclosure overnight." ... "It slung a patch within an impressive three days of Google's Project Zero 90 day patch-or-die disclosure policy"
If it's only 3 days into the 90 day patch-or-die timescale, would it not be more responsible for Google / Ormandy to hold off for the 90 day period (or at least a little longer) so the patch isn't a rushed job? It would also give admins time to apply the patch as well - given it's so 'trivial' to exploit.