• News/
  • https://www.bleepingcomputer.com/news/security/expressvpn-bug-leaked-user-ips-in-remote-desktop-sessions/

ExpressVPN bug leaked user IPs in Remote Desktop sessions

BleepingComputer
·
Bill Toulas
·
Published Jul 21, 2025
·
Updated

ExpressVPN has fixed a flaw in its Windows client that caused Remote Desktop Protocol (RDP) traffic to bypass the virtual private network (VPN) tunnel, exposing the users' real IP addresses. One of the key premises of a VPN is masking a user's IP address, allowing users to stay anonymous online, and in some cases, bypass censorship. Failing to do so is a severe technical failure for a VPN product. ExpressVPN is a leading VPN service provider, consistently rated among the top VPN services, and used by millions worldwide. It utilizes RAM-only servers that don't retain user data and adheres to an audited no-logs policy. On April 25, 2025, a security researcher known as "Adam-X" reported a vulnerability through ExpressVPN's bug bounty program that exposed RDP and other TCP traffic transmitted over port 3389. Upon investigating, the ExpressVPN team found that the issue was caused by remnants of debug code used for internal testing being mistakenly included in production builds, specifically, from 12.97 (released four months ago) to 12.101.0.2-beta. "If a user established a connection using RDP, that traffic could bypass the VPN tunnel," reported ExpressVPN in an announcement. "This did not affect encryption, but it meant that traffic from RDP connections wasn't routed through ExpressVPN as expected." "As a result, an observer, like an ISP or someone on the same network, could have seen not only that the user was connected to ExpressVPN, but also that they were accessing specific ...

Read full article

Affected Software

1 affected component
ExpressVPN Windows client

Frequently Asked Questions

1

What vulnerability is discussed in the article?

The article discusses a vulnerability in the ExpressVPN Windows client that allowed Remote Desktop Protocol (RDP) traffic to bypass the VPN tunnel.

2

What was the consequence of the bug in ExpressVPN?

The bug resulted in users' real IP addresses being exposed during Remote Desktop sessions.

3

Which software product is affected by this security issue?

The affected software is the ExpressVPN Windows client.

4

How did ExpressVPN address the issue?

ExpressVPN has released a fix to address the vulnerability in their Windows client.

5

What does this incident imply about VPN security?

This incident highlights the importance of ensuring all traffic, including RDP, is properly secured by the VPN to maintain user privacy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203