The key is that essentially all of the data for both images are in both PDFs, so the PDFs are almost identical except for a ~128 byte block that "selects" the image and provides the necessary bytes to cause a collision.
Here's an diff of the 2 PDFs from when I tried it earlier: https://imgur.com/a/8O58Q
Not to say that there isn't still something exploitable here, but I don't think it means that you can just create collisions from arbitrary PDFs.
edit: Here's a diff of shattered-1.pdf released by Google vs. one of the PDFs from this tool. The first ~550 bytes are identical.