mrich, no company's engineers can be expected to spend their days reading every single thread on the company's support forum. I wonder if the researcher(s) reported the issue using Apple's Bug Reporter? It has a special category for Security.
If your company sells software to businesses, the standards are a little higher. Either you make sure such a bug cannot slip through by testing, or you have to make it up in support by at least reading all the new customer questions.
How much effort is it to read the first post of every new thread started there? I bet it can be done by one guy who has basic knowledge of computers, heck just hire a Genius bar guy. :)