The vulnerability should have been disclosed to Tails developers as soon as Hernandez was arrested.
https://www.schneier.com/blog/archives/2017/03/fbis_exploit_...
1) escape from browser into VM
2) escape from VM into host
3) run exploit on host
And yes, vulnerabilities in Tor have been exploited. So it's prudent to hit Tor via nested VPN chains, just in case.