Chrome OSX stores in OSX keychain, out of the box. Which is a fairly secure way to store passwords.
Let's assume for the sake of argument that we are running code on both a Windows machine and an OS X machine, and trying to steal someone's browser passwords. While it is undeniable that the OSX keychain adds a roadblock to the theft, many average users would happily enter their password if the box was displayed when they ran up their browser (even if the browser wasn't the originating process) and likely also fall f…
I'm not really sure there is really any defense yet devised for phishing attacks against 'average non-power users.'
I'm not disputing you though, I think it is a problem. But unrelated to how securely a given app stores sensitive info, which is what OP is about.