With both Windows and MacOS both putting scary warnings and hard to bypass blocking methods on improperly signed software this could eventually lead to developers being ransomed, “pay us big money or we will revoke your certificate”. This is not the only incident like this.
That would also be possible for a successful website or app using pinning. So far there are no public reports of it happening. Would probably also put the CA out of business in no time if they did.
It’s very easy to see two steps ahead on this