@df
Before I switched to Arc had a lot more browser profiles.
If you have a wallet in the same browser profile as another ext that has read/write permissions to all websites (many do) that pushes a malicious OTA update (extensions are frequently sold) there's a lot of attack vectors, such as rewriting txs/addresses.