Response by Werner Koch (GPG), contains some details: https://lists.gnupg.org/pipermail/gnupg-users/2018-May/06031...
>Due to broken MIME parsers a bunch of MUAs seem to concatenate decrypted HTML mime parts which makes it easy to plant such HTML snippets. To me this sounds strictly like a MUA issue, not a PGP/SMIME one. If that's really all it is it does seem massively overblown to me. Why not single out the broken MUA implementations instead of saying "don't decrypt emails OR YOU'LL DIE"? I mean just look at the wild speculation i…
The thing is, If I am reading correctly, it seems like this kind of vulnerability seems totally predictable.