This is exactly the sort of "false sense of security" that Chrome devs are talking about. If someone gets access to your user account -- remotely or not -- then they can do pretty much *anything* with it, including setting up a keylogger or dumping the memory of your running Chrome process.