You think that they do not know that these are the consequences? When vulnerabilities are being exploited in the wild, they know that harm is being done, and then they made a deliberate choice to withhold information that could help prevent that harm. How is that decision not malicious?
There’s no debate, unless you truly believe that intent should play no role whatsoever in how we judge actions, in which case, you disagree with the vast majority of post-Enlightenment society. I don’t think you would like living in a world in which strict liability made every mistake a criminal act.
There’s no evidence that they chose to do nothing. Again, they are probably working on it right now and we should not be surprised to see a backported fix in the coming weeks. There is already a long history of them doing just this; why do you think this time it’s different?