The jar wont get written to /usr/var unless the user is running the browser as root, or some sudo variation I would think. I cant imaine an informed Linux user operating that way, but I suppose there might be some one .
The operative word is "informed." I can imagine plenty of "uniformed" users who would do just that.