The gist of it is that there's a timing attack on fancy stacks of blending modes. Calculating a final pixel color takes different amounts of time for different underlying pixels. So javascript can "scan" and OCR a page, or an iframe in that page.
Ideally cross-origin framing would have been disallowed by default but frames were added to the spec before people spent a lot of time thinking about the same-origin-policy implications.
[0]: https://www.contextis.com/resources/white-papers/pixel-perfe... [1]: http://blog.saynotolinux.com/blog/2014/02/05/whats-that-smel...