It closes a real security hole
The release enforces browser origin validation for browser-originated WebSocket connections, closing a cross-site WebSocket hijacking path in trusted-proxy mode. For anyone running remote or shared setups, that is not cosmetic hardening.