interesting you mention. because Firefox doesn't have a way to disable the single instance functionality which was used on this telegram vulnerability.
one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago.
> removing every part of the --noremote option
What's this now? I'm using that to handle multiple profiles and haven't noticed anything breaking
Which Firefox functionality was used in the Telegram vulnerability? Isn’t this all about the desktop app?