Apple have always acknowledged whoever found any exploits in their OS. It may not be in the update docs, but it is in the security-announce mailing list Apple uses for all updates that have security fixes. https://lists.apple.com/mailman/listinfo/security-announce