Autofill changes the phishing surface

Saved passwords that fill themselves in are genuinely useful, and they change what an attacker has to achieve.

The helpful version of this is worth knowing: a password manager fills a saved password only on the address it was saved for. Shown a convincing fake, it stays empty, which is a quiet and reliable signal that something is wrong. The unhelpful version is a browser that fills forms you did not notice were there, or offers details on a page that has no business asking for them. Noticing when autofill does not fire is a useful habit.

More on Browser security