I guess it also has access to the cookies for all your logins.

You mean a website A can have login/auth cookies of website B, D, Z, HK… etc? SOP doesn't work? Or is there some sort of exploit on top of third party cookies? (Just curious. I don't know anout browser dev/etc).

By the way, they don't have just one web apps. They have A, they have K, and apparently a Z – subdomain is webz, or maybe that's actaully A. Not sure.

Yes, it has access to the internal storage mechanisms of the browser.

I used to use Cookie Auto Delete for years. But when I last checked it seemed unmaintained. I log out of all somewhat important services anyway every time I am done.

For important stuff like banking I use Firefox containers.

Yeah, all of them could have their weaknesses and vulnerabilities. I just hope no attacker hits exactly the stack I use...

Personally I only open Firefox on Linux booted from a read only usb. In theory there could be a firmware vulnerability in the CPU that could let it write persistent data to the UEFI firmware, but I hope the possibility is small.

What makes it doubly funny is that the OP is not even about any browser vulnerability, it's a hole in desktop client IPC