But, in order, to do that. The hacker must be damn smart and extremely patient.
Not really. It's just a modified form of Cross-Site Scripting (XSS). It's becoming a popular form of attack nowadays after DDoS coz the traditional email spam methods are no longer roping the hackers success.
U would start to wonder y hackers start to get desperate and even start hitting the revered and supposedly secure MacOS ecosystem with malware.

