As far as I understand, and correct me if I'm wrong, but it would require local access or your mobile network operator to be compromised with a malicious insider, generally I think the risk is limited albeit possible. Given the prevalence of these devices we will soon hear if there's real world exploits. Notably, I do not see the exploit published anywhere either. I'm not saying it is safe, although I would not be turning off my mobile data given the risk here.
The biggest risk would be on public WiFi. Mobile operators should be able to block the exploited as most work as CG-Nat.