More people seem to use it to mean that the software maintainer has had no time to react to the vulnerability. It’s a zero-day when I find it, a one-day when I report it, and very possibly a 180-day when you release your actual patch for it. But quite a few people also seem to use it the way you suggest. It’s always about how long some “reference defender” has known about it, but people’s idea of who the “reference defender” is seems to vary.
More people seem to use it to mean that the software maintainer has had no time to react to the vulnerability. It’s a zero-day when I find it, a one-day when I report it, and very possibly a 180-day when you release your actual patch for it. But quite a few people also seem to use it the way you suggest. It’s always about how long some “reference defender” has known about it, but people’s idea of who the “reference defender” is seems to vary.