1: https://support.apple.com/en-us/HT208860 2: https://knowledge.digicert.com/alerts/ALERT2562.html
EDIT: Its also worth mentioning that this isn't just limited Symantec certs but also will include GeoTrust, thawte, & VeriSign certs. Symantec's cert business has now been taken over by DigiCert so there is a means for valid reassurance.
EDIT2: Also it will effect RapidSSL. Totally forgot about them.
The limited distrust (for older certs issued prior to June 2016) was activated in Firefox 60 and Chrome 66 much earlier this year.
Google blacklisted ALL Symantec certificates since Chrome 66, in April. The roadmap announced the change for October but they did it 6 months earlier, ignoring their own roadmap.
As the OP says, organizations using Symantec have already been hit very hard, by surprise.
Paypal.com is still operating with a Symantec signed cert - issued by "Symantec Class 3 EV SSL CA - G3". Works fine in Chrome 68. (and not in Firefox with the security.pki.distrust_ca_policy override set)
[1] https://support.google.com/chrome/a/answer/7662561?hl=en
"The SSL certificate used to load resources from https://(domain) will be distrusted in M70. Once distrusted, users will be prevented from loading these resources. See https://g.co/chrome/symantecpkicerts for more information."
Everything was being done in 2 waves. First wave was Chrome 66, second wave is Chrome 70. See Google's link above for the specifics.
Source: Chrome's own warnings and that I work for a business that deals heavily in SSL sales.