The good part is that Chrome actually encrypts them, it doesn't keep them in plain text. The bad part is that if someone has physical access to your PC while you're logged in, or guesses your Windows password, they can decrypt them anyway. It really depends on how paranoid you are and who's hanging around your place, honestly.
If you want maximum protection without sacrificing convenience, the trick is to use an actual password manager (like Bitwarden, 1Password, or whatever you prefer) and then disable password saving in Chrome. The password manager asks you for a master password to access everything, so even if someone gets into your Google account or your PC, they won't see anything without that main password. And you can use it across multiple devices without any hassle.
If you don't want to overcomplicate things, at least make sure your Windows has a decent login password (not "1234" or that kind of stuff) and your Google account is protected with two-factor authentication. That combo covers like 90% of the problems. Chrome itself isn't insecure - the real weak point is always us when we use weak passwords or leave the PC unlocked lying around.