The passwords themselves however are encrypted, and the only way to get them back to plain text is through the decryption key – which is your Google password/secondary key. When you sign into Chrome (and sync to the Google servers) your encrypted password is transmitted along with the settings, bookmarks etc. As a result, Google only has the information stored in an encrypted state and do not have the key to decrypt it.
The only way your passwords are not safe is if, your machine becomes compromised.
Also, what happens if google decides to spy on someone? Basically, is it possible that chrome sends some data to google servers even without user signing in for sync?
So once the malware is on your computer, it can get all passwords entered afterwards.
The only harm in saving passwords in Chrome is that the malware can get all passwords at once and does not have to wait for you to login to all important pages eventually.
If the computer is stolen and not given back compromised, then it is safe, because Chrome encrypts the passwords using the Windows password API which encrypts it using the user password