You discover a critical security vulnerability in a popular third-party Android library your app depends on. What is the ethical course of action?
-
A
Exploit the vulnerability to gain competitive advantage
-
B
Ignore it since it is the library author's responsibility to find it
-
C
Privately disclose the vulnerability to the maintainer and allow reasonable time to patch before any public disclosure
-
D
Immediately post full vulnerability details on social media to warn the community