Why is it HTC's responsibility to patch it? Why not a global patch from Android.
Who is "Android"? Do you mean Google?
If so, why should they be responsible - after all, HTC is the one who took a build of Android and customized it for your phone.
In fact between HTC and Google, really HTC *should* be responsible since they are the ones that customized it in a way that you could not just take straight patches from Google.
The problem is of course, that none of the phone makers are serious about security at all (they are making noises, but I'll bet it's just to placate the howling internet). So not only do they not patch Android themselves, they don't want to do the work to even fold in the fixes Google makes.
What would be refreshing is to see a handset maker that really took ownership of the whole system. Sure they would build on Android to start, but they could do so much more - they could have their own security QA team looking for problems, fixing what they found and responding to security vulnerabilities even faster than Google.
They could contribute that work back to Google even, safe in the knowledge it wouldn't even help competitors since they are unable to incorperate Android patches.
Samsung *could* be that company. It's a mystery to me why they are not... they also are making noises about being serious about security but there has been so much hot air in the past around Google and phone makers cooperating "for real" that I refuse to take any statement at face value.