The vulnerability has been deemed critical and assigned CVSS 5.8 severity rating.
This results in anApplication-side script code executionin the invoice of Apple.
The disclosure timeline is below.

Apple has not yet commented on the issue.

source: www.techworm.net