Notably, none of the the algorithms tested in the cited study are Apple's NeuralHash, or comparable algorithms. They look at aHash, pHash (plus a variant thereof), dHash, and and PDQ (used at Facebook for similar applications, apparently). The first 4 date to between 2004 and 2010; the last is more recent, but conceptually similar - the citation [0] for PDQ puts it in the same bucket of 'shallower, stricter, cheaper, faster' algorithms as the first four.
No one has proposed any of those as 'illegal image detectors'. Apple's NeuralHash may or may not be robust to the same or different perturbations but the cited study provides basically no new information to inform the conversation its press release wants to be a part of.
[0]: https://github.com/facebook/ThreatExchange/blob/main/hashing...