This is not the scariest hack that can be done with HTML/JS. There is another one that checks if you are logged in to some web site, your bank for instance. Once a malicious page finds a site you are in, a hidden iframe can click on links and even submit forms on your behalf.