PublicIPChecker

Guide

What is a WebRTC leak?

5 min read · Updated 2026-09-28

WebRTC lets any website read your real public IP — and sometimes your local network IP — even while a VPN is connected. How the leak works, which browsers are affected, and the fixes.

What WebRTC is

WebRTC (Web Real-Time Communication) is the browser standard behind video calls, screen sharing and peer-to-peer file transfer — the technology inside the browser's own Meet, Zoom and Teams experiences. To connect two peers directly, a WebRTC page first gathers ICE candidates: a list of network addresses the page might use for a direct connection — your local Wi-Fi address, your public address, relay addresses.

How the leak works

Gathering those candidates happens in your browser, on your real network — the VPN tunnel does not cover what the page is allowed to read. A malicious (or careless) site can run the candidate-gathering code and display the results: your real public IP, and on some configurations your local LAN address too. The result: a site you visit through a VPN learns your actual address — and the ISP behind it — without any server-side cooperation. In a normal (non-VPN) session the "leaked" address is simply your own, so the practical problem is specifically for people hiding behind a tunnel.

Which browsers are affected

BrowserDefault behaviour
Chromium (Chrome, Edge, Brave…)May expose host candidates including the real public IP; can be restricted with the webrtc.localIPHandlingPolicy setting to private_only or disable_non_proxied_udp
FirefoxHides local addresses by default; the public candidate can still be read in some configurations
SafariRestrictive by default, with historical quirks

Defaults improve year over year — which is exactly why "it should be fine" is the wrong test. Run a check instead.

Check yourself

The home page runs the test for you: the WebRTC local IP row in the browser fingerprint panel. While a VPN is connected, it must read No leak detected — or, at most, show the VPN's address. If it shows your real ISP's address or a 192.168.x.x local address (what a local IP is), the leak is live.

How to close it

  • Chromium browsers: chrome://flags → WebRTC: IP handling policy → set to private_only (blocks public host candidates) or stricter.
  • Extensions: WebRTC LeakProtect and similar add-ons block candidate exposure outright.
  • Privacy-focused builds of common browsers ship with stricter WebRTC defaults.
  • Re-test after every browser update — defaults have changed before, in both directions.

Why VPNs cannot fix this from inside: the browser and its WebRTC stack run on your real network stack before the tunnel is applied to the data. The fix is always on the browser side — settings, flags or an extension — never in the VPN client.

Related: how to hide your IP address and the full multi-leak test in is my VPN working.

Frequently asked questions

Is a WebRTC leak a big privacy risk?

Moderate. It hands a visited site your real public IP (and sometimes your LAN IP) — enough for geolocation-level exposure and correlation with your VPN usage. It does not, by itself, reveal your street address.

Do I need to worry on a normal, non-VPN connection?

Less — the address a page leaks is already your own. The exposure that matters is the real IP alongside a VPN, or the local LAN address in either case.

Does turning the VPN on block WebRTC?

No. The leak happens in the browser's candidate gathering, which sees your real network regardless of the tunnel. Restrict WebRTC in the browser instead.


Keep reading

Check any other IP address

Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.