So 'the bad guys do it' is supporting evidence for it not being 'dangerous or unprofessional'?
The safe, professional approach is to disclose the details but tell Apple that you'll no longer work on macOS until a bounty programme is in place. Then, this *known* bug gets fixed and Apple gets the point that bounties would encourage better 3rd-party security research by the good guys.
Yes it is. They're doing the same thing this guy is doing, but they're not telling anyone. The claim that he somehow just made things more dangerous is unlikely. And publicizing but not disclosing it to Apple is probably more effective at convincing them to institute a bug bounty program, which is his goal. We're talking about Apple's lack of a bounty program right now. Do you think we would be if he just wagged his finger at them? I doubt it. The discourse would be about the bug and its fix. It's actually quite smart of him.