My understanding is that is does not take a "technical genius" to do what can be done with this vulnerability. There are scripts that can be run to automate the "man in the middle" attack. So, if someone wants to do it and can - I don't see it as being too difficult a project.
The bottom line is that this makes the "s" in "https" not reliable or even a lie. If someone wants to get your information, this vulnerability makes it easier.
Never underestimate the abilities of thieves and other scoundrels, even in a "third world country"!
Marilyn