WebRTC leak explained: how your browser can reveal your real IP
How WebRTC in your browser can expose your real IP address despite a VPN, how to check it with the Colitu WebRTC leak test and how to close the gap safely.
You turned on the VPN, a site shows the server's country, and everything looks right. Yet one browser feature can still hand a website your real IP address: WebRTC. It does not affect every setup, it is easy to check, and once you understand how it works, it is easy to fix.
What WebRTC is
WebRTC is the technology behind video calls, screen sharing and file transfers that run directly in the browser, without a plugin. To connect two people as directly as possible, the browser collects possible network paths, called ICE candidates:
- host candidates: the device's own local addresses;
- server-reflexive candidates: your public address as seen from the internet, learned by asking a STUN server;
- relay candidates: an address on a TURN relay server, used when no direct path works.
A web page can start this process with a few lines of JavaScript, and for the basic data channel the browser does not ask for permission.
How the leak happens
The STUN request is a small UDP packet. Whether it goes through the VPN depends on how the VPN is connected to your system:
- Whole-device VPN (TUN or the system VPN service). All traffic, including UDP, enters the tunnel. The STUN server sees the VPN server's address, and that is what the page learns. No leak.
- Proxy only. The browser sends web pages through the proxy, but WebRTC's UDP request can go out directly. The STUN server then sees your real public address, and the page can read it.
So the leak is not a WebRTC bug: the browser is honestly reporting the path its UDP traffic takes.
What is not a leak
Modern browsers hide your local network address behind a random name ending in .local (an mDNS name). If the test shows such a name, that is expected and harmless. Private addresses such as 192.168.x.x are also not your public identity, although privacy-minded browsers try to hide them too.
Test it with Colitu
Our WebRTC leak test asks your browser to gather candidates using Cloudflare's public STUN server (stun.cloudflare.com) and compares the addresses it finds with the address sites see. The result is evaluated only in your browser.
- Turn the VPN off and run the test. Note the public address: that is your real one.
- Turn the VPN on, wait for Connected and reload the test page.
- Compare. Every public address WebRTC finds should now be the server's address, the same one that sites see.
- If your real address from step 1 still appears, WebRTC is leaking.
To check IP, DNS and WebRTC at once, use the VPN connection test. For DNS on its own, see DNS leak explained.
How to fix it
Windows: turn on TUN mode. Colitu for Windows starts in system proxy mode. In TUN mode all traffic, including UDP, goes through the tunnel, so WebRTC sees the server's address. Switch it on in the app settings and run the test again.
Android and iOS. Colitu runs as a whole-device VPN there (Android's VPN service, iOS's packet tunnel), so WebRTC traffic goes through the tunnel as well.
Linux (beta). As on Windows, use TUN mode; it asks for sudo.
Browser options if you want an extra layer or cannot use TUN mode:
- Firefox: typing
about:configand settingmedia.peerconnection.enabledto false switches WebRTC off entirely. - Chromium-based browsers: there is no simple built-in switch; extensions that restrict WebRTC's network use can limit which addresses are exposed.
Keep in mind that turning WebRTC off breaks video calls in the browser, such as web versions of meeting services. With TUN mode you usually do not need to give anything up.
Two common questions
Does a leak mean my traffic is not encrypted? No. Your browsing still goes through the tunnel. A WebRTC leak exposes your IP address to the page that asks, which matters if you use the VPN to avoid being located by sites.
Do apps leak like this too? The test checks your browser. Desktop apps for calls use their own networking; in system proxy mode on Windows some of them may bypass the VPN altogether, which TUN mode also solves.
Make the test a habit
Leaks tend to come back when something changes. Run the test again after you:
- switch Colitu between system proxy and TUN mode on Windows;
- install a new browser or a privacy or "VPN" extension;
- install another VPN, an antivirus "secure connection" feature or a game booster;
- update the operating system or move to a new computer.
Quick reference
| What the test shows with the VPN on | Meaning | Action |
|---|---|---|
| Only the server's address | No leak | Nothing |
| A .local name | Hidden local address | Nothing |
| Your real public address | WebRTC leak | TUN mode on Windows or Linux |
| Your real address on a phone | Unusual | Reconnect, close other VPN apps, contact support |
More in the help centre: connection tests and the Windows guide.