An attacker with physical access to an unlocked Coldcard doesn't need any additional exploit to extract the seed. He can just use the Coldcard at that point.
The vulnerability being discussed may have allowed a *remote* attacker to extract the seed via the USB connection.