The WebRTC (Web Real-Time Communication) implementation in Google Chrome and Mozilla Firefox allows viewing of the public and internal IP address, even if the connection is routed through a VPN server.
WebRTC is an open source app that provides simple APIs to enable communication (voice calls, video chat, and P2P file sharing) through web applications directly from the browser via a standard set of protocols .
It is currently supported by Chrome , Firefox , and Opera web browsers and also works on the Android and iOS mobile platforms .
Researcher Daniel Roesler explains that WebRTC in both browsers is configured to allow the IPs of requests to be submitted to a STUN (Session Traversal Utilities for Nat).
A STUN communicates via UDP and allows a client behind a firewall to communicate with a VoIP outside the local network. It identifies the gateway IP, as well as the internal IP assigned to the client so as to allow direct exchange of traffic with it.
The results of the requests are available in JavaScript, but because they are done outside of the normal XML/HTTP process, they are not visible in the developer console.
Furthermore, Roesler says this is why privacy enforcing plug-ins like AdBlock or Ghostery are unable to block them. “This makes these types of requests available for online tracking if an advertiser creates a STUN with a wildcard,” he says.
The developer created code to demonstrate the information leakage vulnerability by secretly sending requests to STUN servers that record calls. Roesler published his work on GitHub. The demo shows both the external and internal IP addresses of the client connecting via VPN (Virtual Private Network), making it possible to trace the connection path.
The problem is known to Google, who have characterized it as a privacy issue rather than a security issue, and have not reached an agreement on a fix for the issue as the proposed solutions would impact WebRTC.
Disabling WebRTC can be done by installing the WebRTC Block for Chrome, while in Firefox “media.peerconnection.enabled” must be set to “false”.
