In an extreme case imagine that someone sends you a password in a messaging app which is available via the web. If an attacker can trick you to open webpages (maybe they intercept a HTTP site and open a few tabs) they can detect if the page scrolled based on side channels (data transfer) or direct information (did you load a lazy-loaded image from their server?). You can use this to learn page content. This is vaguely similar to https://en.wikipedia.org/wiki/CRIME.
As a concrete example imagine that a webpage has something like this past the first page.
<p>Your password is 56acc1bc03298ec0</p>
<img loading=lazy src=https://cdn.example/secure.png>
If I can trick you to load #:~:text=Your password is 5 and observe that you looked up the DNS for cdn.example and loaded secure.png (especially if that resource isn't cachable) I have learned the first character of the password.If I do this 64 times (on average) I have learned the whole password.
This is a little hard to do, especially with pop-up blockers being built into most browsers so it is hard for a site to open many top-level windows (origin isolation of modern browsers will likely block this in iframes) it is not too extreme of a case.
Of course there are simpler attacks. Maybe someone can link to https://www.youtube.com/feed/history#:~:text=Voice+Feminizat... and they can tell if you have watched this video based on how many thumbnails have loaded. You load too many thumbnails and you get thrown in jail for being trans.