It was almost a week after the release of information about a serious vulnerability in Java Web Start, as Sun recognized its mistake and released an emergency update for Java SE 6 .
It remains to be asked why they did not do it right away when security experts (including from Google) notified them about the discovery of this hole. Was it really necessary to wait for the first exploit to appear on the Web? Especially since the Google specialist himself assures that by the time the information was released, the exloits already existed, and he was forced to publish full information on the Web. However, Sun initially did not attach importance to this threat.
Java plugin for the browser after the update has lost the possibility of running javaws.exe. ')
via threat post