PNG ✕ HTML — same bytes, two identities
An attacker can upload what appears to be an innocent image to a file-hosting service. If any page later embeds it in an <iframe> or serves it without a strict Content-Type, the hidden script runs in the victim's browser.
Always serve user uploads with an explicit Content-Type: image/png + X-Content-Type-Options: nosniff. Never trust the file extension alone.