How about, "It hurts users who have loaded extensions signed with Yahoo's private key, who now have to unload those extensions and find updated versions signed with Yahoo's new private key."
Fer instance.
BTW, "hurt" is the drama-queen way to express the impact. "Inconvenience" is more accurate. Both for Yahoo, and users who have trusted Yahoo's old signatures, as long as the revocation is effective and quick enough to prevent Yahoo-signed malware from getting a foothold.
If that happens, the impact to users escalates beyond "inconvenience" to "big inconvenience" or "real hurt", depending on what gets compromised. "Big inconvenience" == your machine becomes part of a botnet. "Real hurt" becomes a keylogger that transmit your banking or other personal information to an online crim who strips your bank accounts and begins to use your identity fraudulently.