"The validator has to check what the downstream code requires, not merely what the format allows" is the line I would take away, and it names why format-level validation keeps disappointing people. A spec-conformant file is a much weaker guarantee than a file the consumer can survive, and the gap between those two is exactly where these bugs live. The inert-looking part matters too. A .gguf holds tensors rather than code, so it reads as data in a way a pickle never did, and that intuition is precisely what stops anyone asking who parses it. The same reasoning covers any binary artifact a fast parser consumes — fonts, images, model files — where the danger is not executable content but the arithmetic done on attacker-controlled counts before anything gets validated.
