As I understand it, bug bounty awards are a rough proxy for "would nation-state actors be able to exploit this for operational purposes without getting caught".
Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.
Try 10-20 million USD for a zero click iPhone exploit.
thats the true market value of bug bounty awards
the unilaterally set awards by the affected corporation are far lower and based on the price of the researcher’s liability