@rysiek You all remember the WebRTC "IP leak" fiasco from back then, right? Where people could be called on some messengers and before even accepting the call, your own IP would leak to the caller? (And also Natalie Silvanovich showed everyone why it's a bad idea to start the WebRTC state machine prior to accepting a call to everyone because it's a huge attack surface - https://googleprojectzero.blogspot.com/2020/08/exploiting-android-messengers-part-1.html) Pretty much everyone jumped ship back then and agreed it to be a big no no.
This attack here is pretty much the same thing without the need to even make a call. It is way more subtle and therefore even more severe IMO.