cf: "Chromodo" and the vulnerabilities disclosed by this same researcher[0]
[0] https://code.google.com/p/google-security-research/issues/de...
EDIT: And let's not forget TrendMicro's recent blunder with the enabled-by-default HTTP server for "Password Manager" that is installed as part of their antivirus program.[1]
[1] https://code.google.com/p/google-security-research/issues/de...