Or maybe cause it's not a browser security issue :)

Escaping user's inputs depends from the context, that's all.
It's a server-side problem, the application must PROPERLY sanatise inputs.

