In the initial report, I didn't know I could upload videos and I asked them if I can upload my video proof to YouTube (unlisted). They told me not to — presumably because they didn't want this to be public.
It took them until another 9 days (March 14th) to decide that this wasn't an issue. At that point the ticket got marked as "This is expected behavior."
I'm convinced that if this vulnerability is made public, Apple would change their mind about it's severity.
I'm not sure if I can share it, though, as they might use it as an excuse not to pay me a bounty. Thoughts on how to approach this?
PS: I asked them if I could post it publicity after they closed the ticket but haven't heard anything from them.