https://en.wikipedia.org/wiki/Market_for_zero-day_exploits
Selling exploits use to be way more common prior to 2010. Previously many companies wouldn't pay for bug fixes and would periodically sue developers for disclosing issues.
There eventually became a large movement within the cyber security groups about no longer giving bugs away for free and demanding fair market value for exploits (imagine the NSA paying $100k for a zero-day, versus the company giving you $500):
https://threatpost.com/no-more-free-bugs-software-vendors-03...
Nowadays the highly sought out targets like Android or iOS have premiums for zero-days (upwards to $1mil), in-fact it wasn't until Google started paying more for exploits was when Android security started getting better. But if some companies aren't willing to pay fair market value for their exploits, why should it matter if you sell it to someone else?
But yeah, it probably is