Which is why you provide patch notes, and why the more conservative consumers won't even auto-accept patch updates. The point is that a bug fix that doesn't change the API, and which only changes behavior to match intent and documentation, is something that requires minimal testing by the user.
I.e., "fixed possible race condition where..." is a patch.
It may be that a consumer relied on a particular bug when developing, yes, and that fixing it now 'breaks' their application, but that's a definite minority, and why you communicate out the fixes (and for auto-adopting patch releases, you ideally still have automatic tests to validate).