This is an absurd and unfair hit-job.
Let me just spell out, for emphasis, what the article actually says:
* Logging in to a Google service via its website will now automatically show you as logged in to Chrome in the top-right corner. This will provide you with the OPTION to explicitly opt-in to syncing your browser data with the Google cloud by clicking a big blue button that clearly says "Sync as " and then clicking through one of the two clearly-labelled options to confirm that you do indeed want to turn on sync in the following dialogue (which does in fact have a prominent "Undo" button in case you clicked by mistake).
* The entire extent of the alleged practical user privacy issue is that a user might accidentally click the first button, and THEN mistakenly click on the small "Want to manage sync and personalisation before they're turned on? Visit Settings." link instead of the larger, more prominent "Undo" button. This, the blog alleges, will turn on syncing without a chance for the user to undo. (Although, at least as of 69.0.3497.100, this is just plain false - there's an "Undo" button even on the settings page. It may have previously been true; I have not checked.)
* The entire extent of the alleged GDPR violation is that the privacy policy erroneously says that when you sign into Chrome with your Google Account, data is synced with Google's servers, when in reality it isn't unless you explicitly consent. (This was true at the time that the post was written, but the privacy policy was tweaked to correct the factual error - compare https://web.archive.org/web/20180924020748/https://www.googl... vs https://web.archive.org/web/20180924123556/https://www.googl...) For what it's worth, I see no reason why briefly and accidentally claiming to process some data in a consent-ignoring way when you don't actually do so would be a GDPR violation, and the article does not elaborate on this particular legal theory.
Other commenters here have already explained that this change offers security/privacy benefits to some users by protecting them from a failure mode in which they wish to sign out of Chrome on a shared computer (in order to not sync their browsing history to a friend's or family member's account), but instead they only sign out of, say, Gmail, and thereafter end up inadvertently syncing their browsing history and passwords to their friend's Google account instead of their own. Connecting the browser login and Google web service login eliminates that privacy-violating failure mode. That seems like a real gain to user privacy and security to me, and it seems plainly absurd to argue that it's actually a loss on the basis of a hypothetical in which the user accidentally clicks through clearly-labelled buttons in two different dialogues and therefore accidentally enables syncing. That seems doubly true given that even in that hypothetical scenario, syncing can, per the article's own admission, then be immediately disabled (and all synced data deleted).
I'm not an uncritical fan of Google, but criticising them for this is bullshit.