In his personal blog Grossman has described how a malicious website could create form text fields, probably invisibly, for the contact info it wanted to extract from a Safari user.
FORBES: Internet Explorer Remains Vulnerable To Autofill Flaw, Says Researcher