I believe that graykey was able to try passcodes at a faster-than-should-be-allowed rate, which does indicate a flaw but not a serious one.
It certainly seems like GrayKey bypassed a fundamental SEP protection, which would constitute a very serious flaw. The SEP protections are supposed to be a whole 'nother level (which is what this article gets at.. it's Hard to even get at the firmware).
If that aspect of the SEP is compromised, what else about it is? This is extra disturbing because Apple's "fix" was to disconnect unauthorized peripherals -- not, apparently, a fix to the SEP itself. This is why I am stunned there was not more coverage of this. It's smoke that indicates a really fundamental flaw in the SEP.
[1] https://www.apple.com/business/site/docs/iOS_Security_Guide.... (page 18)