This is speculative as I haven't tested out this vulnerability or attempted to avoid it (yet), but I imagine this means it would be a good idea to make password fields "uncontrolled"[1] if you're using react.
The apps I've worked on weren't full SPAs, so I just used plain HTML for the login form.