This is actually an argument in favor of public disclosure of vulnerabilities. Lemi Orhan Ergin was catching a lot of criticism yesterday for posting it on twitter, but if this bug had been reported privately, it would have taken much longer to fix, while malicious actors would be able to exploit it all along.
It was "reported" about a month ago on Apple's support forum. So it does seem likely some people out there were aware of it before Apple became aware.