WebRTC Metadata and IP Leakage in Modern Browsers: A Cross-Platform Measurement Study

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Koysha, Ahmed Fouad Kadhim, Boyaci, Aytug, Akdeniz, Rafet
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917024003784704
author Koysha, Ahmed Fouad Kadhim
Boyaci, Aytug
Akdeniz, Rafet
author_facet Koysha, Ahmed Fouad Kadhim
Boyaci, Aytug
Akdeniz, Rafet
contents Web Real-Time Communication (WebRTC) enables real-time peer-to-peer communication, but its Interactive Connectivity Establishment (ICE) process can unintentionally expose internal and public IP addresses as metadata. This paper presents a cross-platform measurement study of WebRTC metadata leakage using current (2025) builds of Chrome, Brave, Firefox, and Tor on desktop and mobile platforms. Experiments were conducted across semi-trusted Wi-Fi and untrusted mobile carrier networks. Results show that Chrome remains the most leakage-prone, disclosing LAN or Carrier-Grade NAT (CGNAT) addresses on mobile and metadata on desktop; Brave avoids direct IP leaks but exposes session-stable mDNS identifiers; Firefox provides strong protection on desktop but leaks internal IPs on Android; and Tor consistently prevents all forms of leakage. We introduce a structured threat model for semi-trusted environments and evaluate the limitations of mDNS obfuscation. Finally, we propose layered mitigation strategies combining browser defaults, institutional safeguards, and user controls. Findings demonstrate that while direct LAN leakage is declining, emerging vectors such as mDNS and CGNAT create persistent privacy risks requiring protocol-level redesign and policy action.
format Preprint
id arxiv_https___arxiv_org_abs_2510_16168
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle WebRTC Metadata and IP Leakage in Modern Browsers: A Cross-Platform Measurement Study
Koysha, Ahmed Fouad Kadhim
Boyaci, Aytug
Akdeniz, Rafet
Cryptography and Security
C.2.0; C.2.2; K.6.5
Web Real-Time Communication (WebRTC) enables real-time peer-to-peer communication, but its Interactive Connectivity Establishment (ICE) process can unintentionally expose internal and public IP addresses as metadata. This paper presents a cross-platform measurement study of WebRTC metadata leakage using current (2025) builds of Chrome, Brave, Firefox, and Tor on desktop and mobile platforms. Experiments were conducted across semi-trusted Wi-Fi and untrusted mobile carrier networks. Results show that Chrome remains the most leakage-prone, disclosing LAN or Carrier-Grade NAT (CGNAT) addresses on mobile and metadata on desktop; Brave avoids direct IP leaks but exposes session-stable mDNS identifiers; Firefox provides strong protection on desktop but leaks internal IPs on Android; and Tor consistently prevents all forms of leakage. We introduce a structured threat model for semi-trusted environments and evaluate the limitations of mDNS obfuscation. Finally, we propose layered mitigation strategies combining browser defaults, institutional safeguards, and user controls. Findings demonstrate that while direct LAN leakage is declining, emerging vectors such as mDNS and CGNAT create persistent privacy risks requiring protocol-level redesign and policy action.
title WebRTC Metadata and IP Leakage in Modern Browsers: A Cross-Platform Measurement Study
topic Cryptography and Security
C.2.0; C.2.2; K.6.5
url https://arxiv.org/abs/2510.16168