This is 'just' a skill issue. Culturally, it's seems this is not a process they're very good at running. A bunch of similarities to their App Review process which isn't well regarded.
Fuck you, pay me applies.
Do you agree with this statement? If not, I think there's a contradiction. You are morally obliged to do the right thing even if there are entities who don't.
Being hard-nosed about refusing to pay a bounty on a privilege escalation bug is a rookie mistake. It engenders ill will and cements your relationship with security researchers as adversarial rather than cooperative.
When people realise this is what they can expect from Apple they will just sell these exploits to intelligence agencies instead for who knows what purpose.
So congratulations Apple of fucking over not just this person but your entire customer base for years to come. Morons.
I presume some in the list did received bounties?