Novel attack against virtually all VPN apps neuters their entire purpose

https://lemmy.world/post/15102687

Novel attack against virtually all VPN apps neuters their entire purpose - Lemmy.World

So I gave the article a glance and it’s a bit beyond me can someone give me an eli5?

My understanding is that if you run a rogue discoverable DHCP server in a local network with a particular set of options set and hyper-specific routing rules, you can clobber the routing rules set by the VPN software on any non-Android device, and route all traffic from those devices through arbitrary midpoints that you control.

But IANANE (I am not a network engineer) so please correct my misinterpretations.

this implies physical access or at least access within the network?
It has implications on the effectiveness of VPNs on public networks.