@bagder A TL;DR for the vuln/backdoor that should make the severity clear to readers:
Apple's build of curl has silently disabled CA pinning support and allows any certificate signed by a CA the system trusts to be used where the application expected only to accept one explicitly trusted by the application author or user.