This really isn’t an issue. If someone is already on your computer and logged in, you are fully compromised already. If the passwords are stored in your browser then they can use those passwords to change your passwords as well.
Storm in a teacup, but “Microsoft bad” so this will do well here.
If you’ve already got malware on your machine that can exploit this, how or where the passwords in your browser are exposed is entirely irrelevant.
This is just another one of these non-issue “vulnerabilities” where your computer has to already be completely cracked wide open to be exploited.