Since they never released the exploit, in reality we have no way of verifying this is actually true. It very well could be the case Tails still has this vulnerability.
1) escape from browser into VM
2) escape from VM into host
3) run exploit on host
And yes, vulnerabilities in Tor have been exploited. So it's prudent to hit Tor via nested VPN chains, just in case.