Couldn't an attacker cause online (watch-only) wallets to display malicious receiving addresses?

If I understand correctly, one of the main perks of using a deterministic watch-only wallet is the ability to generate new receiving addresses without syncing with the offline wallet, but this seems vulnerable to attack. Example: To prevent an attacker from stealing her funds, Alice keeps her (…)

