Assuming the server receives the requests in the same order as the requests were sent, which on mobile networks isn't anywhere near so certain.
The real deal here is, it depends on some js code updating the dom for each key press, which is BAAAD. Not an useless keylogger, because it reminds a vulnerability product of choosing a bad decision.
Like React with JSX?
This is 127,286,426,869 (~128bn) times smaller than 92^8.
Edit: Note that if you have a repeated character in your 8 charcter password then the number of permutations of the set of 8 (7 distinct) characters is further halved to 20,160.
Edit: nm. My mistake, not as easy as that using only css!