Someone with access to any unencrypted HTTP stream - think ISP or wifi-sharer or (especially) government or cybercriminal - can slip in javascript that, in one browser window, gives the attacker the information needed to decrypt the secure streams in other browser windows.
They do not need to find an exploit in your browser to jump from an insecure browser session to your secure sandbox beside it.
Then, the server can decide whether or not to attach cross origin resource sharing headers to the response. If those headers exist, the response is exposed to JavaScript. If not, they are swallowed by the browser.
I wonder if at some point we're going to have a backlash against JS apps, which are really just the fat clients of the 1990s in a new container, as attackers discover more and more exploitable weaknesses in client JavaScript implementations.