This is a little misleading because it's not the Ledger hardware wallet that is vulnerable, it is the app running on a pc that is vulnerable and even then it can't get anywhere near your private keys or sign any transactions, it can only attempt to fool you.
I absolutely consider the Ledger hardware wallet to be 100% safe at this point. This vulnerability exploits software, human error and irresponsibility not any kind of hardware issue.
It's quite simple to verify the receive address is a valid address to your ledger by looking at the actual Ledger device and that is the point of having a hardware wallet in the first place, because you don't trust a computer and you verify everything on a secure isolated piece of hardware that can't be attacked.
The hardware is still 100% foolproof, but are people? Not even close.....