It's not plaintext, but it looks like any program on the same computer and that knows your password can get the decryption key.
https://superuser.com/questions/146742/how-does-google-chrom... Firefox stores its passwords as plaintext by default, but you can set a master password that prevents easy decryption. (You could probably sniff it out of a running instance, or keylog it as you type it at the beginning of a session, but it's enough that Chrome's password import fails.)
Edit: Firefox's is also encrypted I guess, but they say anyone with access to your computer can get them unless you set a master password. https://support.mozilla.org/en-US/kb/password-manager-rememb...