What do other browsers do differently to prevent this from being a problem?
My first Firefox security bug report (five years before I became a Mozilla employee!) was for a somewhat similar issue where pages could read form autofill data that wasn't explicitly entered by the user. Even before that vulnerability was fixed, it required significantly more user interaction than this Safari exploit. Normally Firefox will not make autofill data accessible to scripts except in response to user interaction.
Details here: http://www.advogato.org/person/mbrubeck/diary/92.html