Mozilla · Firefox · CVE-2018-12399
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 63
**Description**
The issue is related to the registration of new protocol handlers, where the API accepts a `title` argument that can be misleading about the domain registering the handler. This may lead to users approving a protocol handler they otherwise would not have. The vulnerability is also described as being related to insufficient access control in the Firefox browser API, which could allow a remote attacker to substitute the user interface using a specially crafted `title` argument.
**Recommendations**
For versions prior to 63, update to version 63 or later to resolve the issue. As a temporary workaround, consider restricting the approval of new protocol handlers to minimize the risk of exploitation.