The spec has been [updated](https://github.com/whatwg/html/pull/6362) to help protect against mutation XSS. See https://bughunters.google.com/blog/5038742869770240/escaping-and-in-attributes-how-it-helps-protect-against-mutation-xss