appears countless ‘flaws’ are there on intent and additional additional (or changed) with Every single new iteration of browser and HTML version.
This is just encoding a configuration file in the JPEG to cover https://www.darkexploits.com/product/extremely-silent-jpg-exploit-new/