Stealing passwords from infosec Mastodon - without bypassing CSP | PortSwigger Research – https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
“My next test was with Chrome autofill - would the password get filled in automatically by Chrome? Of course it would, and without any user interaction!”
This is one of the reasons why your password manager should never be integrated with your browser.