And suddenly it became legal to decompile code to find exploits. Awesome!
Yes, there's a requirement for interoperability, but "interoperability" is construed broadly. Interoperability in law relates to "interfaces", including APIs, and compatible file formats. Conceivably the term could also be used to describe an antivirus program which protects the program in question.
That's good this is allowed. Besides, bad faith actors will reverse engineer for malicious purposes, regardless of the law.
Exploits by themselves aren't good or bad - their use for malicious purposes is.
See also: adversarial interoperability.