WebRTC Leak (2026): What It Exposes and How to Stop It

Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.

A WebRTC leak happens when your browser’s real-time communication feature, the one behind in-browser video calls, reveals an IP address the VPN was meant to hide. To connect calls directly, WebRTC asks outside servers, called STUN servers, how your connection looks, and that answer can include your real address. Modern browsers now hide your local network address by default, but your public IP can still leak in some setups, TrustMyIP explains.

This page explains what a WebRTC leak exposes, when it happens, how to test for it, and the fix for each browser.

WebRTC Leak: What It Exposes

AddressWhat it isStatus in 2026
Local IPYour device’s address on your home networkHidden by default (mDNS) in major browsers
Public IPYour internet provider’s address for youCan still leak via STUN in some setups
IPv6 addressA second, often unique addressCan leak if the VPN doesn’t cover IPv6

Local addresses are mostly solved. Chrome, Firefox since version 70 and Safari since version 13 replace local IPs with random .local names, a technique called mDNS, privacyscore.dev notes. Old versions, changed settings or corporate policies can undo that.

The public IP is the one that matters. It identifies your internet connection and rough location, which is exactly what a VPN hides, and a WebRTC leak can undo the location change covered in our VPN location guide. Our guide to what a VPN hides explains the rest.

Get NordVPN →
Full-device VPN app
WebRTC leak: which addresses can be exposed, and their status in 2026

When Does a WebRTC Leak Happen?

Browser extensions and proxies are the usual risk. A full-device VPN app routes the browser’s STUN requests through the tunnel, so sites see the VPN’s address. A browser-only proxy or extension may not cover them, which is why FunWithText recommends a full-tunnel VPN over an extension on Chrome, Edge and Safari.

Split tunnelling and IPv6 add risk. A browser excluded from the tunnel shows your real IP by design, and an IPv6 address the VPN doesn’t handle can slip out. Our split tunnelling guide covers the first; our DNS leak guide covers a related leak.

Read: Check Your VPN Is Working →
IP, DNS and WebRTC tests

How to Test for a WebRTC Leak

StepWhat to do
1Disconnect the VPN and note your public IP
2Connect the VPN and open a WebRTC leak test
3Compare: any address matching step 1 is a leak
4Repeat in each browser you use
5Test again after browser or VPN updates

Browsers differ, so test each one separately for a WebRTC leak. Our Chrome VPN guide explains why extensions behave differently from apps. Settings can reset after updates, FunWithText notes, so a clean result today isn’t permanent.

How to test for a WebRTC leak in five steps

How to Stop a WebRTC Leak, Browser by Browser

BrowserFixTrade-off
Firefoxabout:config, set media.peerconnection.enabled to falseBrowser video calls stop
Chrome, EdgeGoogle’s WebRTC Network Limiter extensionSome call features limited
BraveWebRTC IP handling policy: Disable non-proxied UDPCalls keep working
Any browseruBlock Origin’s WebRTC protection optionCovers local IPs
All of themA full-device VPN app, not an extensionProtects the whole connection

BrowserLeaks recommends Google’s own extension for Chrome, WebRTC Network Limiter, which offers several protection levels. In Brave, the setting sits under brave://settings/privacy, and new installs start on Default, which can leak, FunWithText notes.

Need video calls? Turning WebRTC off breaks them. Keep a full-device VPN on instead, or use a separate browser for calls. A kill switch stops traffic if the VPN drops mid-call, which matters most on public Wi-Fi. For stronger browser privacy overall, see our privacy VPN guide.

How to stop a WebRTC leak in Firefox, Chrome, Edge and Brave

How We Research

The mDNS defaults come from privacyscore.dev; the public IP risk and uBlock Origin option from TrustMyIP; the Brave setting, extension advice and re-testing from FunWithText; the Firefox setting and Chrome extension from BrowserLeaks, whose free test is at browserleaks.com/webrtc. We read all sources on 28 September 2026. NordVPN is one of our affiliate partners. Our full approach lives on the About Us page.

WebRTC Leak FAQ

What is a WebRTC leak?

It’s when your browser’s WebRTC feature reveals an IP address, such as your real public IP, that your VPN should be hiding.

Does a VPN stop WebRTC leaks?

A full-device VPN app should route WebRTC requests through the tunnel. Browser extensions and proxies may not, so test to be sure.

How do I disable WebRTC in Firefox?

Open about:config and set media.peerconnection.enabled to false. Browser video calls will stop working until you turn it back on.

How do I stop WebRTC leaks in Chrome?

Chrome has no built-in switch. BrowserLeaks recommends Google’s WebRTC Network Limiter extension.

Is my local IP still exposed by WebRTC?

Not in current Chrome, Firefox or Safari on default settings, which hide it with mDNS. Old versions or changed settings can still expose it.

The Verdict

A WebRTC leak exposes the address your VPN should hide, most often when you rely on a browser extension rather than a full-device app.

Test each browser, use the browser’s own fix where one exists, and keep the VPN app itself on.

Read: DNS Leak Test →
The other common leak
Scroll to Top