Bugzilla – Bug 16717
Security issue with image exclusions
Last modified: 2012-04-25 22:21:53 UTC
The use of images as exclusion areas, especially when combined with the shape-image-threshold property are a security concerns because through script, malicious code could analyze the content of a cross domain image.
For example, if the attacker uses 1px x 1px inline elements around and inside an image exclusion and uses script to find the position of the element, information about the image will be leaked and will allow reconstruction of a grayscale version of the image.
Copying the above comment to 16112
*** This bug has been marked as a duplicate of bug 16112 ***