A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a type confusion error in HandleColumnbreakOncolumnSpanningElement() and potentially execute arbitrary code on the target user's system. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None