It's bad enough that the VEP was bypassed, but the high-profile, 7-figure payout for the security researchers who had their hands on the bug is a problem too. Plenty of bug bounty programs have remote code execution at $10k, but the FBI paid _100 times_ that. That's an amount of money that some bug hunters might find very challenging to turn down. And this is "above board", with no shady bitcoin payments from dingy IRC channels.