Earlier quoted context omitted.
I'm not aware of any legal action taken over malware served up from add on a website. But if it were to happen, the website is who is sue, because it is within their responsibility to ensure that ads and/or content should not cause harm to a visitor.
> it is within their (the website) responsibility to ensure that ads and/or content should not cause harm to a visitor. I don't think that's been established. With the current state of advertising on the internet, it's not even possible to do this. In general, websites use advertising networks which do not allow them to proactively vet the content. Even if they did, no amount of vetting can guarantee the content is b…
Exploits in jpg/png are very rare.
At worst, all you have to do is make the ad network [re]compress the image.