For a while there's been an anti-pattern where a piece of software leaves a localhost daemon running (often without proper security) for web integration.
XSRF vulns also have existed where e.g. a web page can blinding attempt to hit your router's page to change your DNS servers by knowing common router admin sites and default home network topologies. This isn't as useful in today's HTTPS world.
Browsers have been adding more partitioning between local and internet resources to prevent this sort of thing. But that does mean simply putting localhost entries in a hosts file to blackhole a site can now cause an issue.
For a while there's been an anti-pattern where a piece of software leaves a localhost daemon running (often without proper security) for web integration.
One of the more famous abusers was Zoom: https://infosecwriteups.com/zoom-zero-day-4-million-webcams-...
XSRF vulns also have existed where e.g. a web page can blinding attempt to hit your router's page to change your DNS servers by knowing common router admin sites and default home network topologies. This isn't as useful in today's HTTPS world.
Browsers have been adding more partitioning between local and internet resources to prevent this sort of thing. But that does mean simply putting localhost entries in a hosts file to blackhole a site can now cause an issue.