https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...
"Earlier this year Google's Threat Analysis Group (TAG) discovered a small collection of hacked websites."
"We estimate that these sites receive thousands of visitors per week."
"TAG was able to collect five separate, complete and unique iPhone exploit chains, covering almost every version from iOS 10 through to the latest version of iOS 12. This indicated a group making a sustained effort to hack the users of iPhones in certain communities over a period of at least two years."
Google was responsible in identifying estimated scope. They didn't say it was widespread or impacting millions of devices. And that there are vulnerabilities of 2 years worth of iOS versions is pretty reasonable evidence that this has been a 2 year project.
Meanwhile Apple's counter-claims sound like pure damage control with no supporting evidence. They claim it was only operational for 2 months. Yet they provide no justification or evidence for that claim. They are in no position to monitor what happens on the web as they don't crawl it, and don't even attempt to explain why there would be exploits for 2 years of OS versions if this was only operational for 2 months.
But I'm not seeing any reason to believe Google was anything but responsible in its disclosure, nor that they sensationalized it in any way.