Chrome: plz fix security hole that has been around too long
google.com
google.com
If you're concerned about other users stealing your passwords, don't let them use your profile at all.
Every browser has to store passwords in a way that's recoverable (as they need to be sent to the server), so if you store them and you lose control of your computer, you WILL most probably lose control of your passwords too, in every browser including IE9 (something this page, http://www.thewindowsclub.com/chrome-firefox-show-passwords-..., does not seem to understand).
Anyway, it has to be possible to retrieve the password in plain text for Chrome to be able to use it. Even if they remove the functionality to view it, someone could just make a tool - and when someone has access to your computer they could run said tool.
If someone malicious has access to your computer and it's not locked, you're pretty much screwed - that's not the fault of Chrome.
Firefox does the same btw except they offer a master password, but what happens when you misplace that password? Chrome seemingly assumes that the profile password is that master password which seems like expected behavior to me, I mean how many nested passwords do you need to be satisfied?
Also if you have access to the machine saved passwords can still be dug up regardless.
Also understand Chrome needs to be able to get at the clear text at some point, and that you can get at it with JS. Adding a session/timeout based master/login password (like ssh keychain for example) to autofill pw, would be one idea to plug some of the holes.