And in this analogy you can't just change the locks since you have no idea what is specifically wrong with the lock. That's why this is not very good. No one with good intentions would come to this zerodium and give them an exploit. If a find something i report it to the the company that made it and i make my device and all devices more secure.
Anyone who will deal with this "company" are immoral ***** in only for the money.
Immoral, yes, but we are talking about well over a million dollars here. Money talks. How many people can honestly claim that they won't be honestly tempted if they ever found themselves in the exact same scenario?
That said - what's stopping the seller from double dipping? E.g.: first selling the exploit to the security company (or even multiple companies), then selling that same exploit to Apple to have it patched once I have received the money from the former?