antivirus – Is is safe to skip virus scanning for image files?

No, it is not safe to skip scanning images. Do a search on the CVE database for JPEG and PNG and there’s no shortage of entries. A more in-depth search of the NVD shows 6 critical-level JPEG CVEs for the last twelve months, and 3 for PNG. Granted, none of the descriptions I skimmed suggest that they’re vulnerabilities in default, core OS services the way that the classic MS04-028 was.