Earlier quoted context omitted.
The scope of the potential damage is rather huge and can't really be overstated. It's akin to handing over your entire working OS memory to a person, complete with all encryption keys, session tokens and whatever documents you're working on. Potentially, anyway. The working proof-of-concept attacks I've seen use a lot of CPU to read memory and they read slowly, but those are proof-of-concepts and it would not be terr…
Has there ever been a real-world attack of this type? All kinds of things are possible, but you don't cut your leg off because theoretically you might possibly one day get gangrene from an ingrown toenail.
https://leaky.page/ Is a good example
The proof of concept code has been further mitigated by removing high precision timers from JavaScript in most/all browsers; however it is not terribly difficult to create code which bypasses that restriction.
The only thing that’s prevented more investment into this method of attack is that it has essentially no value due to everyone being immune.