WebPKI Observatory — Governance Risk

Root program oversight coverage has collapsed from 67.8% (Chrome) and 78.0% (Mozilla) of incidents in 2019 to 18.4% and 9.9% respectively in 2025, with Apple at 5.4% and Microsoft at 0.0%. Chrome has logged 718 oversight bugs but substantive engagement in only 290, while Mozilla's 814 bugs include just 46 recent substantive actions, indicating declining review depth as incident volume scales. Microsoft's zero participation in public oversight creates a structural accountability gap for the 142 roots it uniquely trusts, while the overall decline suggests root programs cannot sustain coverage of the 223 incidents disclosed in 2025 alone.

Return to WebPKI Observatory