I agree they’re bugs, but the impact being far greater should justify special treatment - and it does. You’ve got bug bounties, special access and even special devices for security researchers, if you count Apple’s program where they’ll let research be done on a special iphone.
The resources to find security bugs should be weighed against the impact of them being found & exploited by bad actors, not weighed against spending those resources on other things. (And small/simple products won’t suffer as much if a problem is found, so those cases justify smaller security investments)
The resources to find security bugs should be weighed against the impact of them being found & exploited by bad actors, not weighed against spending those resources on other things. (And small/simple products won’t suffer as much if a problem is found, so those cases justify smaller security investments)