Really sounds like the vulnerability for PGP is really more akin to XSS more than anything. So email clients that only understand plaintext should be fine.

That also mean utilities like pass should be fine

@hikerus admittedly I may have skimmed that paper and could have missed something.