A website asks for an image and the file picker highlights image files. That guidance helps selection, but it does not establish that every submitted file is safe or even of the expected type.
The MDN accept reference explains that the HTML attribute guides the picker rather than validating the upload. The application still needs appropriate server-side checks.
For an ordinary user, read the site’s stated formats and size limit. If a file is unavailable in the picker, check its actual format before changing anything. Renaming an extension does not convert the contents.
For a developer testing an owned form, use harmless sample files with known types. Check the picker guidance separately from the server’s response to an unsupported file. Keep test data non-sensitive and do not use another person’s upload service as a testing target.
An actionable bug report can say that the interface offered a format the server later rejected, with the sample’s type and size. That describes the mismatch without claiming a security vulnerability from the picker alone.
Good upload design aligns the visible instructions, browser hints and server rules. Each has a different job: helping people choose, explaining rejection and enforcing what the application can safely process.
Editorial illustration from the site’s image collection.

