WebRTC Leak Test & Fix

Prevent browsers from exposing your real IP through WebRTC STUN requests while a VPN is active.

WebRTC enables real-time communication in browsers (video calls, voice, some CDNs). To establish peer connections, browsers query STUN servers and may discover local network interfaces and your ISP public IP — even when a VPN tunnel carries normal HTTP traffic. That is a WebRTC leak: the site you visit learns addresses that should stay hidden.

Test for WebRTC leaks

  1. Connect your VPN and wait until the client reports connected.
  2. Open rookvpn.com/check/vpn-leak-test/webrtc.
  3. Review candidate IPs. Pass: only VPN exit or harmless local candidates consistent with tunnel docs. Fail: your home ISP public IP or LAN ranges (192.168.x.x, 10.x.x.x) appear as reachable from JavaScript.
  4. Repeat in every browser profile you use for sensitive work (work Chrome, personal Firefox, mobile WebView).

Document results alongside your full leak test workflow.

Why VPN alone is not enough

System-wide VPN routes IP packets but browsers implement WebRTC in user space. Some VPN clients add filters; many do not touch STUN. A page can request ICE candidates before your ad blocker runs — test after installing extensions.

Browser mitigations

Firefox: Open about:config, set media.peerconnection.enabled to false for maximum blocking, or use strict Enhanced Tracking Protection profiles. Re-enable when you need WebRTC calls.

Chrome / Edge: Use extensions explicitly marketed for WebRTC leak prevention, or run a separate browser profile with WebRTC disabled for research. Enterprise policies can enforce WebRtcUdpPortRange constraints — consult your admin guide.

Brave: Shields reduce some tracking surface; defaults change between versions. Always verify with RookCheck rather than assuming.

Safari: WebRTC exposure differs on iOS vs macOS; test on the device you travel with.

VPN client options

Prefer TUN/full-tunnel modes in Hiddify when available on your platform. Split-tunnel or “proxy only” modes may leave WebRTC on the physical interface. Combine OS-level VPN with browser mitigations for high-risk users.

Corporate and journalistic workflows

Researchers often use a clean browser profile with WebRTC disabled, VPN connected, and no personal Google login. After investigation, close the profile to discard storage.

Check the result

Reconnect the VPN and rerun the WebRTC check. Host candidates in private ranges and your old public IP should be gone. A candidate that is the VPN exit can stay. If a video call breaks because you blocked WebRTC, use a per-site exception instead of turning the check off and calling the leak fixed.

Browser updates reset flags. After an update, run the check again before you assume last month’s about:config change is still there.