By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: ExpressVPN fixes a bug which could have disclosed user IP addresses
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > ExpressVPN fixes a bug which could have disclosed user IP addresses
News

ExpressVPN fixes a bug which could have disclosed user IP addresses

News Room
Last updated: 2025/07/22 at 12:05 PM
News Room Published 22 July 2025
Share
SHARE

ExpressVPN has updated its Windows app to patch a vulnerability which could have exposed a user’s IP address to observers.

As one of the best VPNs, ExpressVPN is very secure but mistakes can happen. The provider said in a blog post that code meant for internal testing “mistakenly made it into production builds.”

Only users in specific conditions were affected, but the bug meant traffic wasn’t being routed through the VPN tunnel as expected – however encryption was not impacted.


You may like

ExpressVPN acted quickly to fix the vulnerability and is recommending all its Windows VPN users upgrade to the latest version of the app.

The code meant for internal testing found its way into production build versions 12.97 to 12.101.0.2-beta.

It was reported to ExpressVPN in April 2025 by security researcher Adam-X through the provider’s bug bounty program – where security researchers can earn cash rewards for reporting vulnerabilities and flaws.

ExpressVPN said its team confirmed and triaged the report within hours.

The vulnerability centred around Remote Desktop Protocol (RDP). According to ExpressVPN there was only a risk when an RDP connection was in use or when other TCP traffic was routed over port 3389.

ExpressVPN said “if a user established a connection using RDP, that traffic could bypass the VPN tunnel.”

“This did not affect encryption, but it meant that traffic from RDP connections wasn’t routed through ExpressVPN as expected.”

It added that observers such as internet service providers could see that a user was connected to ExpressVPN and that they were using RDP to access remote servers – information that would ordinarily be protected.

RDP is most commonly used in enterprise environments, and therefore most users were unaffected. However ExpressVPN said it considers “any risk to privacy unacceptable.”

A fix was released five days later in version 12.101.0.45. The researcher confirmed the issue was resolved and ExpressVPN closed the report at the end of June.

(Image credit: SOPA Images / Getty Images)

How severe could this have been?

ExpressVPN analysed the issues and believed “the likelihood of real-world exploitation was extremely low.”

Given the fact a majority of ExpressVPN users are individuals as opposed to enterprise customers, the provider said “the number of affected users is likely small.”

For a hacker to exploit the vulnerability, they would’ve needed to be aware of the bug and find a way to route traffic over port 3389. This could’ve been done by tricking a user into clicking on a malicious link or compromising a popular website to launch a drive-by attack – all while the user was connected to the VPN.

As demonstrated by Adam-X, a user’s real IP address could’ve been revealed. But browsing activity couldn’t have been seen and encryption was not compromised.

ExpressVPN said it was grateful to its community for notifying it of potential issues and suggesting improvements. The provider will strengthen its internal safeguards to ensure this doesn’t happen again.

Today’s best ExpressVPN deals

We test and review VPN services in the context of legal recreational uses. For example: 1. Accessing a service from another country (subject to the terms and conditions of that service). 2. Protecting your online security and strengthening your online privacy when abroad. We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Samsung Odyssey S27FG810S
Next Article Power Up for Less: Take 44% of the Price Tag of This EcoFlow Portable Power Station
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

AI Will Protect Your PayPal And Venmo Accounts Against Scams – BGR
News
Interview With Chainwire’s CMO on Redefining Crypto PR | HackerNoon
Computing
Trump World duped by fake Jerome Powell resignation letter
News
6 Tips for Mastering Seasonal Content Planning Across Multiple Clients – The Gain Blog
Computing

You Might also Like

News

AI Will Protect Your PayPal And Venmo Accounts Against Scams – BGR

6 Min Read
News

Trump World duped by fake Jerome Powell resignation letter

3 Min Read
News

Apple Seemingly Working on Sleep Score Feature for Apple Watch

2 Min Read
News

Windows 11’s new update will add a bunch of AI features

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?