This is true up until the point that someone finds a security issue with an image parser that’s present in a browser engine, and suddenly you have an RCE.