The www.com might not be easy to get, but there is probably a www name at another important TLD that can be purchased. And if you own that domain you can easily get SSL certificates too.
Sounds like Chrome could now be a phisher's best friend…
It appears that it only does it for anything subdomainish -- that is, not the first part after the TLD. I tested it against .nz which has a silly mix of .{co,govt,school}.nz second-level domains and directly registered example.nz domains and it always displays at least one "registered" bit.
Which is almost worse because it seems like people have put thought into this.
Sounds like Chrome could now be a phisher's best friend…