What I tried to underline towards the end. Low ≠ zero, and not reliable ≠ not viable.
News sites seem to peddle this as another serious vulnerability. The kind making NSA know mom is angry one didn’t wash socks for a week. This attack scenario is indeed nonsensical at this point. Even if occasionally possible in the wild, it’s too unreliable. This applies to this entire class of attacks.
This doesn’t discredit the authors in any way. During wars, both in proper military warfare and in Cold War, even less reliable methods were deployed and countermeasures against them designed. Because at some point even 1 in 1000 attempts may be a gold nugget. Equally, making a thousand attempts on a high-value target is not a problem in politics and business. Remember you need just one incriminating recording to destroy opponent in a presidental race or blackmail competition in the board.
Most importantly, the authors did correctly outline the threat model. The assumption is: the machines are already compromised, the data exfiltrated and already collected in large quantities. Now, 0.01% may seem tiny until you multiply this by a billion data instances. It’s still not the same level as a reliable RCE, which is a threat from both individual and population perspectives, but it’s also not nothing.