"[...] this vulnerability requires the ability and opportunity to install a malicious app on the target device, which would indicate a complete compromise or the ability to execute code on the targeted device."
Further, this applies while opening a login via Webview instead of your native browser.
You should be fine as long as you don't grant a shady app the auto-fill permission.