You think this is the bug they're relying on?
Actually... yes. Memory corruption bugs are harder to exploit quietly, because if you get something wrong you'll get a crash instead of code execution. Missing certificate validation is much safer to exploit.