What is the point of new confirm admin email process?

As stated in the announcement post:

A few account security enhancements have gone into WordPress 4.9. The
intention is to make it more difficult for an attacker to take over a
user account or a site by changing the email address associated with
the user or the site, and also to reduce the chance of a mistaken or
erroneous change causing you to get locked out.