I think the spec authors and browser vendors are more than savvy enough to know that "img tags don't run scripts" is a security-relevant promise that authors will rely on; I'm not so convinced it's uniquely unreliable compared to the many other security-relevant corner cases out there.
There are other reasons to treat user-provided content specially, whatever format, so maybe you end up in a similar place no matter what. I just don't want folks to be left thinking that the behavior here is unspecified or such.
WARNING: MIGHT FREEZE YOUR BROWSER/OS. CLICK AT YOUR OWN RISK. https://983.github.io/website/random/slow_1.svg
EDIT: interesting, your link made FF sweat, but it didn't stop working when I closed the tab - I had to manually kill the offending process.
Insane.
Being able to upload arbitrary files has enabled many many web security bypasses, with the result ranging from xss to csrf.