This isn't about URL shorteners at all. The issue is a particular “feature” of major ad platforms: in your ad, you can show a link on a domain that you don't own.
Let's say I've built a version of Firefox that sends your cookies back to me, and now I want to distribute it. I can set up a phishing page, then buy an ad on Google that shows https://www.mozilla.org/firefox/ instead of my URL.
This has already happened with GIMP [1], and I suppose many other opensource / freeware apps, too. This is just one example of an attack this “feature” makes possible.
Here we are not talking about a « real hyperlink ». Ads are just showing the vanity URL, very much like they could show some text or image. Browser cannot protect users if they click on something that resembles a link without being one.
Let's say I've built a version of Firefox that sends your cookies back to me, and now I want to distribute it. I can set up a phishing page, then buy an ad on Google that shows https://www.mozilla.org/firefox/ instead of my URL.
This has already happened with GIMP [1], and I suppose many other opensource / freeware apps, too. This is just one example of an attack this “feature” makes possible.
[1]: https://www.bleepingcomputer.com/news/security/google-ad-for...