For a brief moment there I thought that Google finally decided that event listeners added by extension’s content scripts should not receive synthetic (untrusted) events by default. I mean, we’ve had that in Firefox at least a decade ago. Quite a showstopper for exploiting extension vulnerabilities.
No, that was merely a bug in my code…