The labs team at work wrote a bit [0] about why this is over-hyped (more context in the full post): > Arbitrary code execution is bad! But exploiting this vulnerability requires local access at a minimum, compounded by the attacker needing to exploit a relevant device to gain a foothold on the system. This list of valid footholds is quite limited. For instance, an attacker would need to perform code execution in the…
So, every serious company should be concerned that their competition (maybe abroad) will be able to eventually decrypt a lost / stolen laptop with trade secrets. So every corporate laptop needs its full-disk encryption upgraded. It's large.