For a while there's been an anti-pattern where a piece of software leaves a localhost daemon running (often without proper security) for web integration.
One of the more famous abusers was Zoom: https://infosecwriteups.com/zoom-zero-day-4-million-webcams-...
XSRF vulns also have existed where e.g. a web page can blinding attempt to hit your router's page to change your DNS servers by knowing common router admin sites and default home network topologies. This isn't as useful in today's HTTPS world.
Browsers have been adding more partitioning between local and internet resources to prevent this sort of thing. But that does mean simply putting localhost entries in a hosts file to blackhole a site can now cause an issue.
I wonder what kind of person says 'Yes' to this prompt. It gives me the heebie jeebies.
Safari and Firefox allow this by default without a prompt or visible indicator (but maybe that has changed now that Chrome added its dialog).