When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.
https://www.mozilla.org/security/advisories/mfsa2018-02/
https://usn.ubuntu.com/3544-1/
https://bugzilla.mozilla.org/show_bug.cgi?id=1321619