I would expect it's much more likely that a client would have a vulnerability that allowed attackers to obtain private keys (this already happened with lume) and if there were a vulnerability in safari, chromium, firefox etc it would be used for a much more valuable target than nostr private keys at which point it would be identified and patched.