Exploiting the result will involve some social engineering. Starting with getting one of the colliding objects accepted into the repo you want to attack.
At this point, it's cheaper to generate a SHA1 collision than it will be to fix git not to use SHA1. Which is deeply worrying.
Basic hygiene at this point probably includes only merging git commits from others that are gpg signed (as well as gpg signing as many commits yourself as you can without going mad at the password prompts). Unfortunately, tooling doesn't make this easy, and some things like git format-patch are actively unhelpful by not preserving gpg signatures.