If your PGP private key has a good passphrase then you are still OK. This attack suggests that there is some value in how most PGP implementations attempt to protect the private key locally.
As a counter example, Signal Messenger does not even try to protect the private key or saved messages except with a short pin (and that is a new feature). That is probably based on the idea that any local attack is going to end up being a complete compromise of the end point ... which is not an unreasonable assumption. Then you can sniff any passphrase without any extra trouble.
In the end, message security is endpoint security.
This attack is entirely generic. It seems odd that the authors only mention the possibility of a PGP compromise and ignore all the other messengers out there that could be also compromised by arbitrary remote file access. It would of made things more compelling.