People that talk about security spending miss the inherent imbalance in security: a defender has to find every bug; an attacker only has to find one.
Nobody is saying that Apple's wealth should mean they have no bugs. However, it does mean that they should have reasonable test coverage of critical security code.
Yes - it's obvious that there are bad practices at work here - in particular no strict static analysis. I agree there's little excuse for not adding machine processes that could have helped.
But adding human processes costs time and agility, and as you point out, money cannot replace these.
MM is used to denote an American million = 10^6
10^9 used to be a milliard in British English but is no longer used. It is now referred to as a billion.
10^12 used to be a billion in British English but is now referred to as a trillion.
Edit: http://www.youtube.com/watch?v=C-52AI_ojyQ explains it all quite nicely.