The scary thing is that nowadays everything is backdoored. And developers/product owners can even don't know about it. Obsidian is an electron app, thus uses npm, and with npm we now get like at least one malicious package per month.
If they have package autoupdate it's just a matter of time and effort for an attacker to plant something shady there. This could be simple crypto-stealer, or this could be a way to access people's personal vaults.
This could be a legal loophole to scrape all the data from websites that block you directly. Your users will grab all the data for themselves and you just put some telemetry here and there and here we go, we scrape all the web without even using our own IPs
That's exactly what i think it is. Have a legion of users willingly scraping the internet for you, going behind captchas, logins, and all the mechanisms that was put there to stop bots. With this every user user of the browser is also a bot. Now i wonder if the agent string will be something unique, and certain places will just block those browsers from their websites by it.