It's not macOS firewall, but Apple's implementation of OpenBSD's pf used in Apple's macOS. Mullvad is clearly pointing at a bug in OpenBSD's "packet filter", mentioning that it's used in macOS.
Mullvad's article lacks proper wording and shits on the wrong target.