Having looked over the source article, I could not find anywhere that states physical access is required.
I did find the section that states remote execution (from a website) is not possible simply because websites cannot execute the low level code required to exploit the vulnerability. However, that same section also stated that malicious apps installed on the affected devices can exploit the vulnerability.
Did I miss something in that original article?
Also, FWIW, this affects a lot more than just older Apple GPUs. Also affects AMD, Qualcomm, etc. Intel, Arm, and nVidia are not affected.