AFAIK browsers rely on an old version of xslt libraries and haven’t upgraded to newer versions
They also seem to be putting pressure on the library maintainer resulting in them saying they’re not going to embargo security bugs