Essentially - it's reading user-defined data - which is probably enough to be really bad, incase of a malicious exploit in the wild.
Scenario for attack: Laptop looks up a website, DNS request is made to pi-hole, pi-hole sends request to internet. Response packet received back is actually from an attacker, that uses a known vulnerability in the handling of the packet to take over the machine.
Attacker can now see what DNS requests are being made, and by returning custom responses, it can MITM any HTTP request you make from your laptop. Let's hope everything is encripted via TLS, and hope that some piece of software that just asked for admin permission didn't just install a new TLS trust root.
I'd encourage anyone to try that out
Pihole is a system wide Adblocker and so is NextDNS on iOS. So are the ones you can install on Android rooted.
Relevant adventure with iOS update rejection: https://adguard.com/en/blog/adguard-pro-is-back.html