ExpressVPN disables split-tunneling on Windows due to DNS leaks

ExpressVPN disables split-tunneling on Windows due to DNS leaks

ExpressVPN has temporarily suspended use of its split-tunneling feature on its Windows app due to a bug that wasn’t properly directing DNS requests to its servers. The bug was initially discovered by CNET’s Attila Tomaschek, who contacted ExpressVPN after observing the issue on his Windows computer.

ExpressVPN released a statement on its blog disclosing the problem and stating, “Although the issue is believed to involve less than 1% of users on a single app platform, Version 12 for Windows, ExpressVPN rolled out an update that disabled split tunneling on that platform entirely, to minimize the potential ongoing risk to customers. The feature will remain deactivated while engineers investigate and fix the problem.”

Split-tunneling is a feature that allows users to pick and choose which apps and programs they wish to route through a VPN and which they want to keep routed through their own local network. 

Normally, when a user is connected to ExpressVPN via split-tunneling, their DNS requests for the chosen apps are sent through an encrypted connection via the VPN’s servers. Due to this bug, however, it “allowed some of those requests to go instead to a third-party server, which in most cases would be the user’s internet service provider.”

The bug is believed to have started in May of 2022 with version 12.23.1 and continued through until this February with version 12.72.0. 

Thankfully, ExpressVPN stated that the bug is likely to have only affected “1% of users on a single app platform, Version 12 for Windows.” It further added, “We were only able to replicate the issue when using the specific split tunneling mode ‘Only allow selected apps to use the VPN,’ and even then, we found that it only occurred in some cases. In our testing, users who had not activated split tunneling at all, or who had chosen the other mode, ‘Do not allow selected apps to use the VPN,’ had their DNS requests handled properly. No other VPN protections, such as encryption, were affected.”

For the time being, the split-tunneling feature has been disabled and will remain so until ExpressVPN has released an official fix. If you wish to continue using split-tunneling, Version 10 of the ExpressVPN’s Windows app is still available and working correctly.

Time Stamp:

More from PC World