But he wasn't describing a technique for decoding messages that have already been sent. He's only claiming an attack on future messages.
With control of the CA, the attacker can just advertise a bogus public key for the victim in the key server, giving him access to future messages. He can now intercept and relay.