It may be worth noting that we do not really know what do they mean by "logs". These can be either database records or simply text logs generated by a web server sitting in front of the OCSP backend and logging the requests, regardless of what those requests are referring to. In other words, it does not have to be a conscious decision to "harvest IP addresses" but could easily be a side-effect of what the infrastructure does.
Still, it is no excuse for them as one would expect clear and thorough security/privacy audits before rolling out such features. Especially from companies like Apple.