From the description given, I assume this is using timing differences to tell the size of each compressed tile, which gives you info on it's contents. This is certainly not helped by the ability for an apparently untrusted iframe to apply a transform to a target that the security model would normally disallow reading pixels from, amplifying the data from this side channel. Without that it's "just" another sidechannel attack.