In almost all cases immediate disclosure is better for end users who actually care about their security because they can take appropriate mitigation measures.
Just because the vulnerability is not disclosed does not mean it is not being actively exploited. It probably is.
Users who don't care about their security do not deserve to be "protected" at the expense of compromising the security of those who do care who benefit from immediate disclosure.