Yes recursive named entity expansion has been used to attack html sites. Since epubs use html5 for epub3 and since the same problems exist with webkits used in ebook viewers, it was probably a good idea. That said, I have no idea if there are malicious epubs in the wild but given there are malicious Word docs and PDFs in the wild, it is just a matter of time.
Last edited by KevinH; 11-19-2017 at 07:40 AM.
|