Are custom FTS3 tokenizers disabled by default on current SQLite versions? The documentation does not mention it (and also doesn't warn of the security concern around enabling them). Otherwise, I do not see how the attack vector discussed in the video could be "fixed". The security guideline recommends disabling triggers and views, which is also a logical remedy, but seems brittle, nevermind also impractical for a wide range of applications.
The documentation on the fts3_tokenizer function merely states that
Prior to SQLite version 3.11.0 (2016-02-15), the
arguments to fts3_tokenzer() could be
literal strings or BLOBs. They did not have to be bound
parameters. But that could lead to security
problems in the event of an SQL injection. Hence, the
legacy behavior is now disabled by default.
However, it does not discuss any mitigations for the case where SQL injections are not needed, because the attacker controls the database file.