The expected tables are replaced by views that execute the arbitrary sql.
Since this attack came to light, SQLite has added features so that an application can ensure that views and triggers do not have side-effects (outside of the database file itself). And if there are no side-effects then the attack is basically harmless. Sure, the attacker can still exfiltrate or corrupt data, but the attacker had to have write access to the database file in order to carry out the attack in the first place, so exfiltrating or corrupting data is not an issue - they could already do that. See a quick summary at https://sqlite.org/forum/forumpost/8beceed68e
Sites like https://sqliteonline.com/ and https://inloop.github.io/sqlite-viewer/ could be perpetually vulnerable if not?
Most of these attacks rely on creation of virtual table. Can that be done using a simple select statement with prepared statements?