We're talking about YouTube in this thread.
> any injected frontend js would have to bypass browser's sandboxing to steal another domain's cookies i.e. a zero day which is beyond your threat model
Where did this random unrelated attack vector come from? We're going talking about running untrusted software on your computer, remember? That's the attack vector we're discussing.
Your point was "malware in random unrelated software won't know where to look for my YouTube session key", my response was "it will".