Apple's published rates are high (up to $1M), but in practice they pay a lot lower.
Almost always it's between a 2-5 magnitude order of difference in price between a bug bounty and what a company like Zerodium pays. When they have a valuable enough customer asking for something specific they'll even give bonus rates between 2x-10x above their normal rates.
Here have a tweet where Zerodium is doing exactly that: https://twitter.com/Zerodium/status/1437884808257024008
Note: not sure they would pay for these private information leaks. They'd probably prefer a local escalation and then do the data collection themselves.
That's an application that will be used by minors to a large extent, meaning they're literally leaving kids the world around unsafe.
How any of this can be legal is beyond me.
Btw they're also targeting pidgin, I'm imagining this might be related to OTR sessions over tor...?
Edit: remembered moodle is used by universities as well, so not overwhelminly but still....
Edit 2: IMHO working or having worked for one of these companies should be a career ending move. Simply not acceptable to be working in this field anymore. Not by legal means of course, but as an industry we should simply consider people who were willing to sign a contract with these criminals to be unemployable. "Sorry we don't do business with turds."
By that same logic we coul include mass ad/surveillance companies like Google and Facebook to the list. IMHO those do way more damage to society as a whole. Where do we draw the line?
We have tons of jobs you're even legally not allowed to do, no matter how profitable. We're literally talking about people who deal in vulnerabilities in software used by minors, with the express intent of keeping these open.
In my book, that is beyond the line. Change my mind.