Sure, if you ask - ofc. i can give you one example:
Cross site scripting / xss exploit, could be one way: injected java script in any search bar or comment section.
This script could potentially access the cookies, without even pro-activly doing anything - just load the page.
And no download is needed for that & "HTTPS" or "HTTP" only is not the solution to prevent xss exploits.
I don't need to go further in detail, its a common method - can be googled easily and is well known.
Injection can also happen in Ads, without any download or something.
These Remember Me cookies are an example of how easy it is to grab the cookies since most of the users store their sessions to easily log in.
And the FBI is warning (again), because this is something that happens too often, its not something you recognize.
"No Script" is a nice Browser extension, can be configured for each website you visit.
I hope that answers your question, I will not go further into this topic, since this is the wrong place.
Appreciated
Best regards,
zotix