Their example of hijacking a BLE keyboard to get passwords seems a bit farcical. I would love to see a PoC of that attack. The API has been available in Chrome for quite a while. I don't think it has been a large attack vector.
All the more reason to use Safari or Firefox, since Chrome is doing something that I don't want any browser to have. (Whenever I install Chrome, I go through and turn off all of the stupid stuff that chrome should never have like web midi, webscsi, webble, etc.)