But it happens this is not news, it's an old hack that hardware wallet users think to be safe against. But this can actually happen to anyone generating a receiving address.
What happened is that they released an “undocumented” feature of the wallet that allows you to prevent the "man in the middle" attack.