It used to be a big deal - you could use the shatter attack to read the contents of text controls that stored passwords, etc:


These days less of a problem. Message injection/sniffing between applications in different contexts doesn't work. Unless you're the administrator, in which case it is game over already.

