Ars did a nice write up on this. It looks like there’s a different vulnerability that was being exploited to gain root access to devices. The current thought is that the factory reset exploit is being used to wipe the device for another attacker to steal it from the first person that got root access.