Sites can see your real location and ISP
Geo-restrictions can still identify you
WebRTC is exposing nothing public
A local IP alone is not an exposure
Nothing to fix right now
What Is A WebRTC Leak?
Your real IP address, exposed through your browser, while you are connected to a VPN.
WebRTC (Web Real-Time Communication) is the technology that lets browsers talk to each other directly for video calls, voice chat, and file sharing. Zoom, Google Meet, and Discord all rely on it, which is why every major browser ships with it switched on.
To connect two peers directly, WebRTC asks a STUN server one simple question: what is my real IP address? That request can slip outside the VPN tunnel, and the answer becomes readable by any website that asks the browser for it. That shortcut is the leak. No permission prompt, no visible sign it happened.
STUN requests can bypass the tunnel
Fixing it is left to you, per browser
Our desktop app blocks leaks automatically
Firewall blocks traffic outside the tunnel
Our extension adds WebRTC Slayer for browser-only
Step 1
Test now
Step 2
Get Windscribe
Step 3
Browser only
Step 4
Test again
Or Do It By Hand, Browser By Browser
Fully disabling WebRTC can break video and voice apps like Zoom, Meet, and Discord. App-level protection avoids that tradeoff.
Chrome & Edge
No native off switch. Install a WebRTC-limiting extension, or use a VPN extension that blocks it for you.
Firefox
Open about:config, search media.peerconnection.enabled, and set it to false.
Brave & Opera
Set the WebRTC IP handling policy in Settings, Privacy, to "Disable non-proxied UDP".
Safari
Restrictive by default. It does not hand out candidates without media permission, so exposure is limited out of the box.
Just want it handled in the browser?
WebRTC Leak vs DNS Leak
Both undermine a VPN, but they expose different things and need different fixes. Windscribe protects against both.
What it exposes
WebRTC leak
Your real IP address
DNS leak
The sites you visit
How it escapes
WebRTC leak
A STUN request from your browser
DNS leak
DNS queries routed to your ISP
Windscribe fix
WebRTC leak
Automatic on desktop, WebRTC Slayer on the extension
DNS leak
Private DNS inside the tunnel
Frequently Asked Questions
What is a WebRTC leak?


A WebRTC leak is your real IP address being exposed through your browser while you are connected to a VPN. WebRTC powers browser-based video and voice calls, and to connect two people directly it asks a STUN server what your real IP address is. That request can travel outside the VPN tunnel, and the answer becomes readable by any website that asks your browser for it. There is no permission prompt and no visible sign that it happened, which is why a leak can run for months unnoticed.
How do I know if I have one?


Run the test at the top of this page with your VPN connected. The page scores the same address family as your connection IP. If the WebRTC row shows a different address from your connection IP, that difference is your real IP escaping the tunnel. If the addresses match, or the WebRTC row reads "Not exposed", nothing is leaking. A local address like 192.168.1.24 or an address ending in .local is your private network address and is not a meaningful exposure.
Does a VPN prevent WebRTC leaks?


Only if it actively blocks WebRTC, and many VPNs do not. A VPN encrypts the traffic travelling through its tunnel, but WebRTC runs inside your browser and can reach a STUN server on its own unless something stops it. That is why you can see a leak on this page while your VPN says you are protected. With Windscribe the desktop app blocks these leaks automatically, and the browser extension does it through WebRTC Slayer.
Do I need to turn anything on in Windscribe?


It depends on what you are running. The Windscribe desktop app blocks WebRTC leaks automatically as part of how it routes and firewalls your traffic, so there is no toggle to find and nothing to configure. If you use the Windscribe browser extension on its own, without the desktop app, open the extension settings and enable WebRTC Slayer. Running both is fine, and the desktop app remains your protection either way.
Is it safe to disable WebRTC?


It is safe for your device, but it has a cost. Turning WebRTC off entirely in your browser can break the apps that depend on it, including Zoom, Google Meet, Discord, and most browser-based calling and screen-sharing tools. That is the drawback of the manual browser fixes. Blocking the leak at the app level keeps your IP inside the tunnel without switching off the technology those calls need.
WebRTC leak vs DNS leak: what is the difference?


They both undermine a VPN, but they expose different things. A WebRTC leak reveals your real IP address, which points to your location and your internet provider. A DNS leak reveals which websites you are visiting, because the lookups for those domains escape the tunnel and reach your ISP instead of a private resolver. Different mechanism, different fix, and a clean result on one says nothing about the other, so it is worth running both tests. Windscribe protects against both.
Does this test store my IP?


No. The check runs entirely in your browser. Your browser gathers its own WebRTC candidates locally and compares them against your connection IP on your device. No result is written to a Windscribe server, nothing is logged against your account, and there is nothing for us to hand over later. You can re-run the test as often as you like.
Which browsers leak WebRTC by default?


Chrome, Edge, Firefox, and Opera all ship with WebRTC enabled, so they are the most common places a leak shows up. Safari is more restrictive and will not hand out candidates without media permission, which limits exposure out of the box. Brave includes built-in WebRTC handling options. Mobile matters too: the in-app browsers inside social and messaging apps run WebRTC as well, so it is worth testing there rather than assuming your phone is covered.
Why does my local IP look like a random string ending in .local?


That is mDNS obfuscation, and it is a good sign. Modern browsers replace your real private network address with a random hostname so websites cannot use it to fingerprint your device or map your home network. It means your browser is doing the right thing. The row is shown here for completeness, but a .local value is not an exposure and needs no action.





