Just your periodic reminder that the dollar figures here aren't apples-apples. Apple will pay you X for a vulnerability, and a broker might pay nX. But n is complicated. The ordinary way it works is that payments are tranched; you're paid in chunks, up to some cap, until the vulnerability is burnt. Once that happens, you stop getting paid, so n can be less than 1.
It's also always worth pointing out, even though it's not relevant to this thread, that the vulnerabilities we're talking about all fit into a similar mold; they're all generally some form of drive-by or click-by clientside RCE (they're some of the harder vulnerabilities to find and weaponize, and, from what we can see in reporting, they're not the kinds of vulnerabilities we see lots of disputes about with vendors, though I'm happy to be corrected).
And, as always, I want to point out that even at these eye-watering figures, vulnerabilities are cheap. The market competition to RCE vulnerabilities and implant kits is human intelligence. You will pay more just in health insurance and benefits overhead to run a single human intelligence program against a target. Every government in the world, from Germany to the Seychelles, can afford what the IC pays for vulnerabilities, and there's probably no figure we can realistically drive vulnerabilities to in the near future that will change that --- Iran can pull this kind of money out from under its couch cushions, and NATO and China's couch cushions are stuffed with it.