Yes. The malicous scripts can already do that. It has taken years to train people and educate them on adding suitable Content-Security Policy headers to prevent such violations without breaking the internet. Every modern technology (especially the XMLHttpRequest) has been more strict on the SOP. However, to introduce a new technology which is more effective than a simple XMLHttpRequest in such a manner that it does not follow SOP when there is no threat of breaking any existing websites is questionable at best.