This is an archived snapshot of W3C's public bugzilla bug tracker, decommissioned in April 2019. Please see the home page for more details.
The use of images as exclusion areas, especially when combined with the shape-image-threshold property are a security concerns because through script, malicious code could analyze the content of a cross domain image. For example, if the attacker uses 1px x 1px inline elements around and inside an image exclusion and uses script to find the position of the element, information about the image will be leaked and will allow reconstruction of a grayscale version of the image.
Copying the above comment to 16112 *** This bug has been marked as a duplicate of bug 16112 ***