I think that reading all of a users' cookies from all websites is pretty privacy invading...
Now they limited it to ".pushbullet.com", but even then they don't need that permission since ".pushbullet.com" is a server controlled by them, so they are free to set and read those cookies anyway.
The cookies permission is only needed if you want to read cookies from a domain you don't own. The extension has no need to modify the cookies, and if Pushbullet wants to set or change them, for example to set session cookies, it can do so in a non-extension tab. The extension can then send those cookies in their API request automatically without needing to access them.