tldr if you're on a malicious website, it can make you unknowingly and unintentionally autofill personal info. Most password managers allow you to disable autofill entirely which is recommended until passwords managers mitigate the attack vector.
edit: this was posted earlier #1088323