Exactly. Project zero consists of some of the best security experts in the world. They also strictly practice responsible disclosure. I can't imagine why anybody would be mad to get such a great review and test for free, from such a great team.
Project Zero discloses the vulnerabilities to the affected 90 days before releasing to the public. It's probable that Apple was notified and patched this because of Project Zero. Once it's been patched or 90 days are up, then Project Zero discloses to the public.
> Sounds like the corporation's problem, willingly ignoring security updates.
A properly vetted update requires both compatibility testing and security testing. It would be irresponsible to push an OS update without verifying that it will not damage productivity or bring down defenses.
Businesses that provide or allow iOS devices need to be ready when new OSes are released to the public, which can easily be done since Apple offers regularly-updated betas for months in advance. This is particularly important because even managed devices cannot be prevented from upgrading to new OSes unless all traffic is routed through controlled networks that block access to Apple update servers.