Epiphany prior to versions 48.1 and 47.5 allows websites to trigger external URL handlers with insufficient user interaction or warning. If the handler application is vulnerable, this opens the door to potential code execution under the user's context. This behavior misleads users and shifts the attack surface to local applications.