Or is a huge surprise (to the typical user) that highlighting text BY ITSELF in one window exposes that information for JavaScript running in a different application (like the browser). It’s like knowing that my smart TV is fingerprinting my viewing habits.
Isn’t the biggest security risk from copy and pasting passwords from a “secure” location to another one?
It looks like with modern browsers, reading the clipboard is gated behind some restrictions. Whew.