ExpressVPN Removes Split Tunneling Feature Over DNS Leak

by | Feb 12, 2024 | News




Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos.

Patreon
Reading Time: 3 Minutes

In a recent development, ExpressVPN has taken action to address a critical flaw in its software, prompting the removal of the split tunneling feature from its latest version. The decision came after the discovery of a bug that inadvertently exposed users’ visited domains to configured DNS servers. The vulnerability, present in ExpressVPN Windows versions 12.23.1 – 12.72.0, released between May 19, 2022, and Feb. 7, 2024, primarily affected users utilizing the split tunneling feature.

Split tunneling, a feature allowing users to selectively route internet traffic in and out of the VPN tunnel, provides flexibility for those requiring simultaneous access to local and remote resources securely. However, a flaw in this feature led to DNS requests bypassing ExpressVPN’s infrastructure and being directed to users’ internet service providers (ISPs) instead. This diversion enabled ISPs to potentially track users’ browsing habits, compromising the privacy and security promised by VPN products.

 

See Also: So, you want to be a hacker?
Offensive Security, Bug Bounty Courses




Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.

ExpressVPN, acknowledging the severity of the issue, addressed the concern after it was reported by CNET’s Attila Tomaschek. The company noted that the bug affected approximately 1% of its Windows users, particularly those utilizing the “Only allow selected apps to use the VPN” split-tunneling mode. Users of affected versions are advised to upgrade to the latest version, 12.73.0, which removes the split tunneling feature altogether.




For users unable to upgrade immediately, ExpressVPN recommends disabling split tunneling to mitigate the risk of DNS request leaks.

Additionally, the company assures users that the split tunneling feature will be reintroduced in a future release once the bug is fully addressed. In the interim, users seeking to utilize split tunneling are advised to download and use version 10, unaffected by the bug.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: [email protected]

Source: bleepingcomputer.com

Source Link

Merch

Recent News

EXPLORE OUR STORE

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.


Join our Community

Share This