Do ereaders (that have a browser) and apps (all apps, any platform) that support Javascript need a setting that disables it? Or at least by default sandboxes if to only allow resources in the file? Or disable it always in an svg?
Javascript Trojans in svg images
Javascript Trojans in svg images






