They can only access it while you’re focused on their webpage. CORS is all about that.
If you click off to another web page and enter information or type of password into a secondary app they can’t gather that. As soon as they lose focus they lose the ability to capture your data.