By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

GadgetBond

  • Latest
  • How-to
  • Tech
    • AI
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Add GadgetBond as a preferred source to see more of our stories on Google.
Font ResizerAa
GadgetBondGadgetBond
  • Latest
  • Tech
  • AI
  • Deals
  • How-to
  • Apps
  • Mobile
  • Gaming
  • Streaming
  • Transportation
Search
  • Latest
  • Deals
  • How-to
  • Tech
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • AI
    • Anthropic
    • ChatGPT
    • ChatGPT Atlas
    • Gemini AI (formerly Bard)
    • Google DeepMind
    • Grok AI
    • Meta AI
    • Microsoft Copilot
    • OpenAI
    • Perplexity
    • xAI
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Follow US
AppsSecurityTech

ExpressVPN disables split tunneling due to DNS leak bug

A DNS leak bug impacted 1% of ExpressVPN’s Windows users over the years, routing browsing data outside the VPN tunnel to spying internet providers when leveraging split tunneling.

By
Shubham Sawarkar
Shubham Sawarkar's avatar
ByShubham Sawarkar
Editor-in-Chief
I’m a tech enthusiast who loves exploring gadgets, trends, and innovations. With certifications in CISCO Routing & Switching and Windows Server Administration, I bring a sharp...
Follow:
- Editor-in-Chief
Feb 12, 2024, 2:06 AM EST
Share
We may get a commission from retail offers. Learn more
ExpressVPN disables split tunneling due to DNS leak bug
Photo: Alamy
SHARE

Popular virtual private network (VPN) provider ExpressVPN has uncovered and promptly addressed a troubling vulnerability in recent versions of its Windows software that allowed internet service providers (ISPs) and other third parties to view some user DNS requests, potentially exposing browsing habits and destroying privacy promises.

The significant bug was introduced in ExpressVPN Windows versions 12.23.1 through 12.72.0, spanning releases from May 19th, 2022 through February 7th, 2024. It allowed DNS leakages for those using the “split tunneling” feature, which intelligently routes some traffic through the encrypted VPN tunnel while other traffic routes outside the tunnel.

While contents of user traffic remained protected, DNS requests that should have been hidden were exposed. DNS requests reveal the domains users visit, providing insightful browsing history to snoopers.

By design, ExpressVPN directs all DNS traffic through its own DNS servers to prevent observation by ISPs, governments, hackers, and others. This bug defeated these privacy protections for affected Windows users with split tunneling enabled.

The vulnerability was discovered and responsibly reported by security researcher Attila Tomaschek of CNET. Tomaschek uncovered that with split tunneling active, some DNS requests were leaking to external DNS servers instead of being securely routed through ExpressVPN’s private infrastructure.

Most commonly, requests were exposed to a user’s own ISP’s DNS server. While this did not reveal specific pages visited or account details, it did expose the sites and services a user connected to.

ExpressVPN releases patch, disables split tunneling

In response, ExpressVPN rapidly patched the affected application versions and disabled split tunneling functionality while they solved the underlying problem.

They noted that only about 1% of Windows users actively leveraged split tunneling and were impacted by the bug. For those affected, visited domains could have been observed by ISPs for over 2 years until the discovery of the flaw.

The company recommends that affected users upgrade to the latest ExpressVPN Windows version 12.73.0, which removes but will later re-add split tunneling once the bugs are resolved. For anyone requiring split tunneling immediately, they advise downgrading to the older version 10 release.

This situation highlights the importance of vulnerability discovery and responsible disclosure for fixing bugs before malicious actors become aware and abuse them. It also illustrates the difficulty of assembling secure, reliable virtual private networking tools.

ExpressVPN’s actions demonstrate their commitment to transparency, integrity, and protecting their users. While a small percentage were impacted for a short period, they deserve credit for their response and dedication to doing better going forward. The intent is not to punish providers when bugs occur but to ensure accountability to do better.

ExpressVPN
App Store screenshot of ExpressVPN, showing the app details with a 4.5-star rating. The image displays three preview panels highlighting features: 160 lightning-fast VPN locations, one subscription for all devices, and customer support. The app icon is red and white, and the screenshot is set against a purple and dark blue background, depicting a smartphone interface.
Image: ExpressVPN

ExpressVPN is a secure channel that creates a tunnel between your device and the internet. It ensures the protection of your data from snooping and censorship. With best-in-class encryption, 24/7 live chat support, and TrustedServer technology, it guarantees maximum security. You can connect to servers in 105 countries and use up to 14 devices at the same time. With lightning-fast speeds, ExpressVPN is the ultimate solution for your online privacy needs.

Try ExpressVPN

Discover more from GadgetBond

Subscribe to get the latest posts sent to your email.

Topic:ExpressVPN
Most Popular

Copilot’s agentic mode auto-handles your Outlook inbox and calendar chaos

Apple Vision Pro successfully guides the first eye surgery

Anthropic’s Claude links up with 9 top creative tools

Google donates AP2 to FIDO, supercharging secure AI agent shopping

Liquid Glass iPhone: subtle curves make bezels vanish forever

Also Read
Google "G" logo in gradient

Google rolls out Preferred Sources worldwide in all languages

An abstract network diagram featuring a central image of a clinician in blue scrubs with a stethoscope, connected by lines to several blurred portraits of diverse people and icons labeled "Agent." Small text bubbles indicate AI functions like "Accessing," "Referring notes," and "Consulting references."

This AI co-clinician from Google DeepMind aced 97 out of 98 clinical tests

Promotional image of the Samsung Galaxy Book6 Enterprise Edition in a sleek gray finish, shown from multiple angles highlighting its slim design, keyboard, and side ports, with the text “Effortless connectivity, elegant design” on a neutral background.

Samsung launches Galaxy Book6 Enterprise Edition with Knox security and Intel vPro

Futuristic illustration of a glowing Earth with radiating data lines, surrounded by icons representing text, audio, images, video, and AI processing, with a central cube symbolizing a multimodal AI system.

Nemotron 3 Nano Omni is NVIDIA’s new open AI model that handles video, audio, documents, images, and GUIs all at once

LG UltraGear evo AI GM9 5K gaming monitor

LG UltraGear evo GM9 goes on sale with 5K, 165Hz, and AI upscaling

Top-down view of a Rivian R2 Performance electric SUV in matte green, showing the front hood, signature oval headlights, and grille as it sits on a paved road with yellow center lines and grass along the edge.

Rivian R2 Performance Launch Package brings lifetime Autonomy+ and more

Adobe and Semrush logos displayed side by side on a dark background, separated by a plus sign, with diagonal purple accent lines on the edges.

Adobe completes $1.9 billion Semrush acquisition

Minimal graphic with the text “OpenAI DevDay [2026]” centered on a light background, with a small green abstract icon of arrows and a circle in the lower right corner.

OpenAI DevDay 2026 is set for September 29 in San Francisco

Company Info
  • Homepage
  • Support my work
  • Latest stories
  • Company updates
  • GDB Recommends
  • Daily newsletters
  • About us
  • Contact us
  • Write for us
  • Editorial guidelines
Legal
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • DMCA
  • Disclaimer
  • Accessibility Policy
  • Security Policy
  • Do Not Sell or Share My Personal Information
Socials
Follow US

Disclosure: We love the products we feature and hope you’ll love them too. If you purchase through a link on our site, we may receive compensation at no additional cost to you. Read our ethics statement. Please note that pricing and availability are subject to change.

Copyright © 2026 GadgetBond. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | Do Not Sell/Share My Personal Information.