From the write up at https://www.ryanpickren.com/webcam-hacking , the bug chain appears to allow script execution in "arbitrary" domain context, which at first glance seems much bigger than just webcam extraction. Sticking up someone's face is attention grabbing compared to what could be done with that kind of power.
Is it because of the first bug in the chain that only the media-permissions was affected by the context confusion?
For example being able to extract cookies or local storage from other contexts would be a much bigger deal (local storage is sometimes used to store XSRF protection keys or other credentials), so I assume that wasn't at all affected?
Did any other parts of safari use the same broken context awareness as the media permissions or do we know that it was it isolated to media permissions?