* Normally you can't access Chrome's decrypted cookie storage unless you're in an interactive session and you've unlocked the keychain.
* An attacker running code on your computer (nefarious NPM package, etc) can spawn a headless chrome session with remote debugging enabled and then slurp out all the decrypted cookies through the remote debugging socket
Chrome is very frightening to me. It's just this massive God program that has a huge attack surface and a lot of really valuable goodies like this that attackers would love to get at.