• News/
  • https://www.bleepingcomputer.com/news/security/expressvpn-bug-has-been-leaking-some-dns-requests-for-years/

ExpressVPN bug has been leaking some DNS requests for years

BleepingComputer
·
Bill Toulas
·
Published Feb 11, 2024
·
Updated

ExpressVPN has removed the split tunneling feature from the latest version of its software after finding that a bug exposed the domains users were visiting to configured DNS servers. The bug was introduced in ExpressVPN Windows versions 12.23.1 – 12.72.0, published between May 19, 2022, and Feb. 7, 2024, and only affected those using the split tunneling feature. The split tunneling feature allows users to selectively route some internet traffic in and out of the VPN tunnel, providing flexibility to those needing both local access and secure remote access simultaneously. A bug in this feature caused DNS requests of users not to be directed to ExpressVPN's infrastructure, as they should, but to the user's internet service provider (ISP). Usually, all DNS requests are done through ExpressVPN's logless DNS server to prevent ISPs and other organizations from tracking the domains a user visits. However, this bug caused some DNS queries to be sent to the DNS server configured on the computer, usually a server at the user's ISP, allowing the server to track a user's browsing habits. Having a DNS request leak like the one disclosed by ExpressVPN means that Windows users with active split tunneling potentially expose their browsing history to third parties, breaking a core promise of VPN products. "When a user is connected to ExpressVPN, their DNS requests are supposed to be sent to an ExpressVPN server," explains the vendor's announcement. "But the bug allowed some of those requests ...

Read full article

Affected Software

3 affected components
ExpressVPN Windows>=12.23.1<12.72.0
ExpressVPN Windows=12.73.0
ExpressVPN Windows=10

Frequently Asked Questions

1

What is the main topic of the article?

The article discusses a bug in ExpressVPN that has been leaking DNS requests for several years.

2

What specific feature was removed from the latest ExpressVPN software version?

The split tunneling feature was removed from the latest version of ExpressVPN due to the bug.

3

What versions of ExpressVPN Windows are affected by this DNS leak bug?

The bug affects ExpressVPN Windows versions from 12.23.1 to 12.72.0 and specifically version 12.73.0.

4

What security implications are discussed regarding the DNS leak?

The security implication involves exposure of domains visited by users to configured DNS servers, compromising user privacy.

5

How long has this bug been present in ExpressVPN?

The bug has been leaking DNS requests for several years.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203