A lot seem to think there's only one way to responsibly disclose vulnerabilities (e.g. https://news.ycombinator.com/item?id=15800676), but that's really not the case at all if end-user security is the priority. It's very likely that quite a few already used this maliciously as well, and the more responsible thing to do in that case probably was to announce it (along with a temporary mitigation) to as many people as possible.
Btw credit to https://twitter.com/fristle/status/935670476214378496 for finding this!