That's still not enough. Even if bad guys are already using the exploit in the wild, it still isn't responsible to immediately make it public. If the exploit isn't already public, that means the bad guys are treating it as something to be traded in secret. (And of course, the only reason we're discussing this is that the exploit is not already public.)
Instantly publishing the details of the exploit may well broaden its use by bad actors, by reducing its market price to zero.