I probably wouldnt have exploited the vulnerability, but based on what you’re saying, youre otherwise you’re doing the right thing imo
- Report the vulnerability responsibly
- Support any/all efforts from their team to document, understand, patch
- Verify an effective & timely patch
- If vulnerability is neglected, protect userbase by publicly whistleblowing