OTOH, security researchers do inflate the value of any given exploit (chain) vs. broad mitigations.
Still, 200k seems _low_ for a bug that should imperil the reputation of a many-billion dollar company. And a few years ago it seems like that would have been $1000 and a firm handshake...