I hope they submitted this to the MEGA Vulnerability Rewards Program https://mega.co.nz/#blog_6
My guess is that it already has, and has been ruled a side-channel/social-engineering attack (requiring either a compromised browser or to run arbitrary javascript on the site).