ExpressVPN bug has been leaking some DNS requests for years
ID: def18c5f-ca12-5cd7-b2ad-ea0d0f962a4b
STIX ID: report--def18c5f-ca12-5cd7-b2ad-ea0d0f962a4b
Feed Name: Bleeping Computer
Threat Score
ExpressVPN discovered a bug in Windows app versions 12.23.1–12.72.0 that, when split tunneling was active, caused some DNS requests to be sent to the system-configured DNS (usually the ISP) rather than ExpressVPN's DNS, potentially exposing visited domains; the vendor removed split tunneling in 12.73.0, recommends upgrading or disabling split tunneling, and will reintroduce the feature after a fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
