If there is no intent to abuse the bug when not paied then there is no additional threat there from simply notifying the company that some threat is already present. How it can become a black-mail?
So every report about discovered bug can be considered as black-mail? If one discovers a bug, reports it to the company and says that after 3 months it will be public it's a black-mail too?
Or the payment request makes it different? And if person doesn't threat to publish the bug then it's ok?
[0] https://www.justia.com/criminal/offenses/white-collar-crimes...
Whoever, with intent to extort from any person, firm, association, or corporation, any money or other thing of value, transmits in interstate or foreign commerce any communication containing any threat to injure the property or reputation of the addressee or of another or the reputation of a deceased person or any threat to accuse the addressee or any other person of a crime, shall be fined under this title or imprisoned not more than two years, or both.
https://uscode.house.gov/view.xhtml?path=/prelim@title18/par...
I agree with you on a moral basis: what difference does it make if I get payed not to publish it vs. If I just publish it without even asking to get paid. But I'm not sure the law would agree with us.
In this case you aren't just a vigilante targetting apple, there is established practice stretching decades.
There is also a duty on you as a security proffeshional, and there is a significant public interest in knowing about the vulnerability. So , most likely, it will be you doing your job.
Most countries have a culture against whistleblowers, starting from childhood ("don't be a tattletale", "don't be a rat").