It looks like it exposes a myriad of vulnerabilities to the interweb. Some of them have been patched, but the password manager API still looks very fragile:
https://code.google.com/p/google-security-research/issues/detail?id=693
https://code.google.com/p/google-security-research/issues/detail?id=693