But doesn't this assume that the 'bad guys' have knowledge of the exploit. This feels like a faulty assumption. However after disclosure the bad guys will definitely have knowledge.
Also after disclosure what is the right course of action? We certainly can't require the replacement of all vulnerable hardware.
Let's break it down for examination. Before disclosure, the bad guys may know and the good guys certainly do not know. After disclosure, both bad guys know and good guys know. Good guys who know can take protective steps.