The diagram in the post has the user device talking to the attacker device over Bluetooth, and the bug description explicitly says "An attacker within bluetooth range" - which heavily implies to me your device actually is pairing with the attacker device somehow! If already being paired with the attacker Bluetooth device is a prerequisite for this attack that's much less of a concern imo.