Some of these claims... "can retrieve data from Chrome extensions (such as credential managers) if a user installs a malicous extension."
News flash, you can do pretty much anything you want if you can get the user to install a malicious extension. That is social engineering, not a side-channel attack.