I would argue that releasing this vulnerability as irresponsibly as he did is showing he cares more about negative publicity than user security.
Yes, it's Apple's fault for poor QA that this was released, but this guy also put users at risk by telling the entire world about it without giving Apple a chance to fix it.
You're right, it's about user security before publicity. So make sure users are safe first.