The authors talk a lot about how you can get everything if you compromise the client machine, but of course if you compromise the client you can compromise everything.
Just install a keylogger to get all typed passwords, send the decrypted hard drive image over the network and run it in a VM proxying network traffic via the compromised machine, no need for any targeted attack.
The fact that they focus on that rather than on an actual interesting attack makes me believe that there is no real vulnerability whatsoever.
"We also found how it is possible to abuse account recovery to ultimately obtain the encryption key for the vault" is really scary, but if it were accurate they would be talking solely about that, so maybe it's just a phishing attack.