I agree that this could be a problem but in this paper in order for the attack method to work the developer of the App would need to explicitly set the keychain attribute with the flag "kSecAttrAccessibleAlways", making the keychain data available even when the device is locked, "Otherwise the credentials of the app are not affected by the attack method."