The problem is that allowing the vendor to define what is responsible, which seems these days to be expanding into giving them unlimited time to fix it, is to allow them to take unlimited time to fix it.
Cooperation or even coordination takes willingness from both parties. Let's look at the actual page apple has on reporting security issues [0]
"When we receive your email, we send an automatic email as acknowledgment. If you do not get this email, please check the email address and send again. We will respond with additional emails if we need further information to investigate a security issue."
Something seems a bit off here. I would have expected a human to get back within a few working days for a serious security problem. That might be in the auto response email, but I wouldn't be surprised if it wasn't.
"For the protection of our customers, Apple generally does not disclose, discuss, or confirm security issues until a full investigation is complete and any necessary patches or releases are available."
Does this extend to the security researcher that reports the vulnerability? If so, that's probably why there was no coordination.
[0] https://support.apple.com/en-us/HT201220
Edit: removed spelling mistake mistake.