I understand that one of the machines at work has bash, and probably most Macs do.
But I also understand that if users haven’t changed the default security settings of their machines, and many (most?) users probably haven’t, then you’ve still got safety nets.
Insights welcome.
For the most part, if you're not running a webserver, this isn't really an issue for you. You should go ahead and patch anyway, but there is no real urgency.
The vast majority of users don't have to worry about this bug on their own systems, except where the rogue DHCP servers come in.