Because the GDPR already has a perfectly reasonable way to avoid the requirement for cookie banners. If you don’t collect information beyond what is strictly necessary to perform the task you are offering to users, and do not use that information other than in the performance of that task, then you don’t need a cookie banner. So Strava would not need a separate permission in order to collect location data for comparing your biking routes, but Strava would need a separate permission in order to use that location data for advertising, and Facebook would need a separate permission in order to collect the location data in the first place.
The GDPR doesn’t specify the technical means, only that permission must be explicit and freely given, with the default assumption being “no permission granted”. I think these conditions are entirely reasonable, and a header that could be set by somebody other than the user, then sent by the browser on behalf of the user, does not satisfy these conditions.