What are really the security concerns with this approach, other than a vm escape?
When a client vm is at a website that asks for a password, the vault vm asks you to confirm there if you would like to share that specific password only with the specific client vm.
I don’t see how this can be exploited on the client side to extract credentials without vault confirmation.
I do not think the protocol itself was designed to be secure. So, if someone exploits the browser, he probably can also use exploit chain to dump the passwords if he finds a bypass. The same concern works for a local KeepassXC, of course, but it is limited to passwords that exist in the same VM.
It sounds pretty impossible that there is an exploit chain that will retrieve credentials without vault consent.
Are there any theories on how this can be done?
Not yet, but there is certain increase of the attack surface. I do not care much, but someone else could.