Earlier quoted context omitted.
It's also easier than "gray market" sales. Bug bounties pay for a wider variety of bugs, including plenty of stuff that's of no interest to your perhaps-Saudi buyers; and they don't require you to develop a weaponized exploit - "hey, I noticed this crashes" is often enough. Plus, less risk of waking up and finding out you've been sanctioned by OFAC or something like that.
curious why Saudi? Are they known to be prolific buyers of vulnerabilities?
China and Russia are on the same boat, but they are far more capable with in-house tech.