Apple doesn't want to patch zero-days used by US authorities in order to alleviate pressure on its encryption practices.
So they really only want to fix zero-days that are known broadly or get media attention. And they don't want to give too much incentive to researchers to report zero-days to Apple instead of selling them to the highest bidder (which may ultimately be the largest governments with the greatest ability to regulate Apple).