Yeah, if your threat model involves not trusting links, you should be disabling JavaScript and CSS by default and probably not browsing the web in the first place. Libpng and other libraries frequently have fairly critical bugs that are a bigger concern than MitM attacks.