So you do not ever support disclosure. Okay, valid stance, though I do not happen to agree with you.
If no one forces their hand, companies have proven, repeatedly, that they will simply sit on known vulnerabilities until hell freezes over. In the mean time, countless millions of systems remain vulnerable. And if one random security researcher could find the exploit, so can government-funded hackers such as Dimona, the Russian mob, the NSA, Bureau 121, etc.
I would rather have critical exploits patched eventually, even if it means two days of increased visibility to the problem. YMMV.