Proton Mail Paid for This Bug … Then Left It Unfixed for 17 Months

Came across this video from Cyberinssider (donno how legit they are!)
As Proton user it makes me worry about Proton’s approach! In short it’s: “a confirmed Proton Mail spoofing flaw can make forged emails appear legitimate and the vulnerability reportedly remained exploitable 17 months after Proton paid a bug bounty for the discovery.”

Has anybody heard anything about this?