This sentence from the doc referenced sums it up well I think:
> A naive implementation of this feature may allow an attacker to determine the existence of textual content across an origin boundary.
Security & privacy implications of that seem obvious, e.g. extracting an account number (or other sensitive information) from a page by searching for successive prefixes.