I'm starting to wonder what useful service these researchers are providing, because if it wasn't for them, would any of this stuff actually be known or useful to anybody? Sure, someone might figure it out on their own, but apart from spies or engineers, who has that kind of expertise? If they're killing my FPS for their willy waving, I'm not amused.
Problem is once these issues start to come to light others will be able to develop them further (standing on the shoulders of giants so to speak). Realistically though unless you've made yourself the target of spies or engineers these vulnerabilities are exceedingly difficult to use in any kind of practical way against every day targets without already having one leg through your security perimeter so if they are you already have bigger security issues to worry about. The real threat is in environments where people already have a foot in the door in unprivileged space such as enterprise systems and other multi-user environments.