Au contraire, the last two weeks have shown Apple actively identifying & eradicating malware before the problems are publicized. This in contrast to, say, Android having a longstanding and largely unfixable password crack (enter a long but wrong password and it logs you in anyway), and Microsoft maliciously abusing customer resources (pre-download Win10 without permission).
Yes, creative malicious people can abuse features to evade security. Seems Apple is doing better than others in finding & fixing such things, making the rare trespasses newsworthy instead of boringly common.
What's your criteria for attributing malice?
My guess on published malware flaws is it has been in the wild and exploited prior to publishing. For every hacker claiming a reward there are several more pissed off because their cash cow was found out.
It would take quite rosy outlook to think nobody anywhere is exploiting malware now that this was found.