I got the first interpretation, but I think yours is what we should be talking about. The responsibility for this bug is not on the maintainer, more so on the company for accepting it into their codebase without any vetting.
They benefit from FOSS as well, so maybe if we could do some adovacy. After all, I support paying taxes and funding stuff that doesn't directly benefit me.
This has parallels to unpaid internships and paying college athletes. Seems sketchy that companies are making money off of what are essentially volunteers.
I was going to say this. Most are just looking for some experience outside school/work and next thing you know they are the only one maintaining something big companies rely on.