Why aren't physically-local attacks in Chrome's threat model?
[...]
We consider these attacks outside Chrome's threat model, because there is no way for Chrome (or any application) to defend against a malicious user who has managed to log into your computer as you, or who can run software with the privileges of your operating system user account.
$ sqlite3 .config/google-chrome-unstable/Default/Cookies 'select * from Cookies limit 1;'
13132674324938999|.codepen.io|__cfduid||/|13164210324938999|0|1|131326....