That's not the hardware wallet being exploited though, it targets the user's computer. Verifying the address on the screen of a hardware wallet during confirmation would reveal the mismatch.
But most HW wallets have tiny screens that make users apathetic to validating tx data.