Its funny that Google says "We encourage responsible disclosure of potential application security issues to security@google.com" yet they didn't reply back to this hacker who exploited the hole.

And you know for sure that he contacted them that way?

