Indeed. This seems to be a very limited vulnerability. Even in optimal conditions, this isn't likely to be able to "steal 2FA from Google Authenticator" because as GPU.zip site itself plainly stated in their FAQ:
>I am a user. Should I be worried?
>Under most circumstances, probably not. Most sensitive websites already deny being embedded by cross-origin websites. As a result, they are not vulnerable to >the pixel stealing attack we mounted using GPU.zip. However, some websites remain vulnerable. For example, if a user who is logged into Wikipedia visits a >malicious webpage, that webpage can exploit GPU.zip to learn the user’s Wikipedia username (as we demonstrate in Section 5.4 of the paper).
So I'm not sure if their claim of being able to steal secure website credentials holds against GPU.zip people claiming it cannot do it.