Isn’t spoofed SSID an old attack? I couldn’t figure what’s new here.
So the attacker doesn't control the wrong network access point, they just make the client connect to it when it thinks it's connecting to something else.
It relies on both networks sharing the same credentials, and at the end, the attacker cannot man in the middle the connection itself. They have just forced the user to connect to a different network than intended.