They've already taken down the shortened link and blog, so they're definitely working on it. It's a major enough issue that they'll definitely work on it until it's fixed. Plus it seems quite likely that it's a random little exploit in blogspot, and I strongly suspect it's the kind of exploit that's impressive while a secret, and turns out to be some stupidly basic trick with a really easy fix.
From what I've seen, the majority of privacy issues like this tend to be an exploitation of a feature, i.e. finding a way to use something that it wasn't meant to be used for. As such, fixing the feature (and/or disabling) resolves it.
Sure, it could turn out I'm wrong, but I think the odds are in my favour.
One thing I know for sure, finding security bugs is never an easy task, nobody gives you anything for free on this world. So when I see people who are thinking like you minimizing it I'm saying to myself people should start thinking twice before releasing their findings for free because nobody gonna acknowledge your work anyway.
First, I haven't said that it was easy to find the bug. Second, I said I hope it's released after it's already fixed, so your "for free" point is pretty irrelevant.