Where is the XML config stored?
If it is backed up with, say, Dropbox, then someone getting access to that could trigger a data export when the user enters the master password next time. And then pick up the data from the synced folder.
This would widen the attack surface from needing local access. Am I missing anything?