[1] https://code.google.com/p/chromium/wiki/LinuxPasswordStorage
edit: Apparently there are people that run either incredibly old versions of chrome or don't run a keystore daemon and actually upload all of their dotfiles to github so I guess that part is technically accurate.
Obviously not a 'secure' system by any stretch of the imagination but it's an order of magnitude better than storing in plaintext.
If you've been hit with an OS compromise you're pretty much SOL, but it shouldn't be so easy to grab highly sensitive data from accidentally exposed profiles.