Seth David Schoen writes:

> if its operator knew a vulnerability in some clients' video codecs,

(or in some other part of Tor Browser, since the proxy can also serve
arbitrary HTTP headers, HTML, CSS, Javascript, JSON, and media files of
various types)

> it could also serve a maliciously modified video to attack them

