To be fair, I think Firefox has this restriction too? I might be wrong, but I could have sworn I ran into some script-injection extensions that weren't working on some sites because of this problem.
It's been a while since I checked, I eventually gave up on the extensions because I wanted to thin out my list and I wasn't comfortable with them overriding CORS headers -- so things may have changed, or maybe I misunderstood the situation even back then.