That's exactly not what they're doing. They aren't creating operating system vulnerabilities. They're telling you about ones that already existed.
What seems more probable is that the same advances that LLMs are shipping to find vulnerabilities will end up baked into developer tooling. So you'll be writing code and using an LLM that knows how to write secure code.