When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.
https://bugzilla.mozilla.org/show_bug.cgi?id=1321619
https://usn.ubuntu.com/3544-1/