How is it ethical to distribute this without first disclosing to apple and waiting for a fix at least a few days?
Delayed disclosure is a nicety, not something you are obligated to do.
By going loud and public, you ensure that the company has to do something to save face. It can't just be forgotten on some manager's desk.
And the fact is, you, as part of the public, would only know about the times when somebody goes loud about an exploit. For all you know, there might have been hundreds upon hundreds of times when security researches have gone to the company and been outright ignored, and when one finally goes loud with what he has found, you say "He really should have done this more quietly, it would have been much more responsible"