Tag: ExpressVPN bug leaked

ExpressVPN bug leaked user IPs in Remote Desktop sessions
News

ExpressVPN bug leaked user IPs in Remote Desktop sessions

A bug that allowed Remote Desktop Protocol (RDP) traffic to evade the virtual private network (VPN) tunnel and reveal users' actual IP addresses has been rectified by ExpressVPN in its Windows client. By hiding a user's IP address, a VPN enables users to remain anonymous online and, in certain situations, get around censorship. For a VPN product, not doing so is a serious technical failure. With millions of users worldwide, ExpressVPN is a well-known VPN service provider that is frequently ranked among the best VPN services. It follows an audited no-logs policy and makes use of RAM-only servers that don't store user data. Through ExpressVPN's bug bounty program, a security researcher going by the handle "Adam-X" disclosed a vulnerability on April 25, 2025, that exposed RDP and ot...