CVE-2018-12399: Medium severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-12399?
CVE-2018-12399 refers to a vulnerability in Firefox < 63 where the API accepts a title argument that can be used to mislead users about which domain is registering a new protocol.
How does CVE-2018-12399 affect Firefox?
CVE-2018-12399 affects Firefox versions prior to 63.
What is the severity of CVE-2018-12399?
CVE-2018-12399 has a severity rating of 4.3 (medium).
How do I fix CVE-2018-12399 in Firefox?
To fix CVE-2018-12399, update Firefox to version 63 or higher.
Where can I find more information about CVE-2018-12399?
You can find more information about CVE-2018-12399 on the Mozilla website and the MITRE CVE database.