I think you are misreading the article, so let me be clear:
If you enter your card in a compromised device, then you lose control over
1) how many transactions are being made
2) who you are paying
3) how much
Because the chip has no way of asking you for confirmation about the identity and amount of the transaction. There is no secure keypad entry connected to the chip or secure bus going out.
All you have is physical presence. The chip can prove to the input device that it is present, and the input device cam forward that proof to the bank. That is all the chip does. It does not prevent you from paying the wrong person, and it does not prevent you from paying the wrong amount. This is why compromised input devices are created, so that you can be charged the wrong amount and to the wrong party when you think you are buying gas.
The chip only guarantees physical presence. Checking the CVV is only when there is no presence and you are trying to milk the attack into an offline attack rather in addition to the MITM attack. Why are offline attacks also possible? Because vendors want to support online purchases, where there is no physical presence. But that' not the MITM attack I was describing.
Offline (card not present) transactions are a second issue, and indeed they are much larger (80-20) not present:present in terms of card fraud, but you don't need shimmers to conduct card not present fraud, although you can certainly use them for that.
Finally, not verifying CVV is not an abuse of the protocol, it's how you do a card not present transaction, which is also supported in the same payment protocol. It's not some weird form of protocol violation vendors are all mysteriously doing. It is not "doing it wrong".