Law & Policy

The Vulnerability Equities Process: When Governments Keep the Bug

August 4, 2026 10 min read Haven Team

A government agency discovers a flaw in a piece of software that millions of people run. It can tell the vendor, so the hole gets patched for everyone. Or it can say nothing and use the flaw to break into the systems of its targets. Both choices protect national interests, and they point in opposite directions. The process for deciding which wins is called the Vulnerabilities Equities Process.


The word "equities" is the giveaway. Different parts of a government have a stake, an equity, in the same decision, and those stakes conflict. An intelligence agency wants capabilities. A defensive agency wants the population's software secured. The VEP is the attempt to arbitrate between them with something more structured than whichever office shouts loudest.

The Dilemma in Concrete Terms

Imagine an agency finds a previously unknown flaw, a zero-day, in a widely used operating system. The flaw lets an attacker run code on any machine running that system. This is a genuinely valuable intelligence tool, useful against a foreign adversary's networks.

It is also a loaded gun pointed at the agency's own citizens, its own government, its own hospitals and banks and utilities, because they run the same software. Every day the flaw stays secret is a day the agency can use it, and also a day everyone else stays exposed to anyone else who independently discovers the same hole. The core assumption behind keeping it, that no one else will find it, is exactly the assumption that cannot be verified.

The nobody-else-knows gamble

Retaining a vulnerability is a bet that no adversary, criminal group, or researcher will independently find and exploit the same flaw before it is fixed. Studies of vulnerability rediscovery suggest that bet is far less safe than it feels, because serious flaws are often found by more than one party.

How the Process Works

In the United States, the VEP was formalized in a charter the White House published in November 2017, which laid out, in unclassified terms, how the decision is supposed to be made. An interagency board reviews vulnerabilities that the government learns about and weighs whether to disclose each one to the vendor or retain it.

The published charter describes factors the board is meant to weigh:

Consideration Question it asks
Prevalence How widely is the affected product used? A flaw in ubiquitous software endangers more of the public if retained.
Severity How much damage could exploitation cause, and how reliably does the exploit work?
Operational value How useful is the vulnerability for intelligence or law enforcement, and is there another way to get the same result?
Likelihood of rediscovery How probable is it that someone else finds the same flaw, turning a retained secret into a shared exposure?

A decision to retain is not meant to be permanent. The charter provides for periodic re-review, so a vulnerability held this year is supposed to be reconsidered rather than kept indefinitely by default. How faithfully that happens in practice is harder to see from the outside, which is much of the criticism.

Why It Became Public at All

Transparency here was won, not granted. For years the process ran with almost no public description. Two events forced it into daylight.

The first was Heartbleed in 2014, a severe flaw in the OpenSSL library that underpinned encryption for a large share of the web. Reporting raised the question of whether intelligence agencies had known about it and stayed quiet. Officials denied prior knowledge, but the episode put the disclose-or-retain question in front of the public. Litigation by civil-liberties groups seeking records under freedom-of-information law pushed the government to describe the process, and an earlier version of the policy surfaced through that route.

The second was more painful. In 2017, a set of powerful exploits attributed to a US agency were leaked publicly by a group calling itself the Shadow Brokers. One of them, targeting a Windows file-sharing protocol, was rapidly repurposed into the WannaCry ransomware, which spread worldwide and disrupted hospitals and businesses in a matter of days. It was a live demonstration of the retained-vulnerability nightmare: a flaw kept for offensive use escaped custody and was turned against the public.

A stockpiled vulnerability is only an asset while it stays secret and stays yours. The WannaCry episode showed what happens when it stops being either.

The Unresolved Criticisms

Even with a published charter, security researchers and civil-liberties advocates raise durable objections:

What It Means for You

The VEP is a reminder that the security of software you rely on is shaped by policy decisions made without your input, in which your safety is one input among several. You cannot influence a given retain-or-disclose call. You can reduce how much any single flaw exposes.

The practical defenses are the familiar ones, and they matter more once you accept that some flaws in your software are known to someone and deliberately unpatched. Patch quickly when fixes do ship, so the window of exposure closes the moment a vulnerability is disclosed. Prefer systems that limit the blast radius of any one compromise. And favor end-to-end encryption, because it changes what an exploited endpoint yields. This connects to the wider market for these flaws, covered in our pieces on the zero-day exploit market and mercenary spyware, and to the constructive counterpart, coordinated vulnerability disclosure, where flaws are reported to be fixed rather than hoarded to be used.

No messaging system can promise that the device in your hand is free of flaws a government has chosen to keep. What strong encryption can do is ensure that the content and history of your conversations are not sitting in plaintext on a server waiting to be requested through an entirely legal front door. Reducing the number of places your data can be taken from is the part that stays in your control.

Try Haven free for 15 days

Encrypted email and chat in one app. No credit card required.

Get Started →