If you have a malicious extension, then under XUL I think it is game over. WebEx probably offers more isolation and/or protection. Also note that a malicious addon can possibly also record passwords that are pasted in manually from a password manager, or auto-typed.
On the other hand a website should not be able to get at any password stored in (or pasted into) the browser except its own.
On the other hand a website should not be able to get at any password stored in (or pasted into) the browser except its own.