[ RECORD YEAR ]2015

WebRTC Local & Public IP Leakage Flaw Disclosed (RFC 5245 / STUN / TURN)

Security researchers published proof-of-concept exploits showing that WebRTC JavaScript APIs in Chrome and Firefox sent unauthenticated STUN packets that bypassed active VPN tunnels and leaked the user's real public and private LAN IP addresses.

THREAT SEVERITY
8.2 / 10
Target TechnologyWebRTC, STUN (Session Traversal Utilities for NAT), ICE (Interactive Connectivity Establishment)
OSI Network LayerLayer 4/7 / WebRTC ICE & STUN UDP NAT Traversal
Threat Actor / AttributionDaniel Roesler (Independent Security Researcher)
Protocol StandardIETF RFC 5245 (ICE), RFC 5389 (STUN), RFC 8828 (WebRTC IP)

01Video Presentation & Conference Keynote

02Deep-Dive Technical Analysis

WebRTC utilizes the Interactive Connectivity Establishment (ICE, RFC 5245) protocol and STUN (RFC 5389) servers to establish peer-to-peer audio/video mesh connections across NAT firewalls. The JavaScript API `RTCPeerConnection.createOffer()` instructed the browser's network stack to query all local network interfaces and configured STUN servers directly over UDP, completely bypassing the operating system's default VPN routing table and allowing any webpage with basic JavaScript to harvest the user's true ISP-assigned IP and internal LAN subnet without user permission or browser prompt.

03Vulnerability & Exploit Flow

Exploit Vector

JavaScript-triggered unauthenticated STUN binding requests bypassing system-level VPN routing interfaces.

04Recommended Defense & Mitigation Protocol

Operator Hardening Strategy

Deploy mDNS local candidate anonymization (`.local` hostnames), browser WebRTC privacy extensions, and firewall UDP STUN port restrictions.

05Security Impact & Geopolitical Consequence

Undermined commercial VPN privacy guarantees for millions of users, prompting browser vendors to implement mDNS hostname obfuscation for local ICE candidates (RFC 8828) and configurable WebRTC IP policy controls.

06Authoritative Standards & External References

07Related Topic Cluster Records

TelcoSec Global Ecosystem · Academy & Enterprise Audits

Master 5G Core, SS7 Defense & Subsea Cable Auditing

Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.

Hands-on SS7, Diameter & 5G SBA Firewall Defense
5G SA Zero Trust Security Architecture & ProLabs
Enterprise Carrier Auditing & Rogue Base Station Interception
Explore SaaS Academy Labs?Enterprise Consultancy (telco-sec.com)?
SaaS Academy free tier · Enterprise audits for operators