Turbo VPN Deploys Emergency Windows Patches After IP Leaks
Turbo VPN, a popular virtual private network service owned by Singapore-based Innovative Connecting Pte. Limited, has released two emergency Windows patches following tests by TechRadar that uncovered persistent IPv4 and IPv6 traffic leaks. The updates, culminating in version 3.7.0.0, successfully resolve the unencrypted data exposures, though questions remain regarding proprietary protocol changes.
Key points
- Turbo VPN, owned by Singapore-based Innovative Connecting Pte. Limited and known for over 500 million Android downloads, faced scrutiny over its Windows client security.
- TechRadar testing revealed active IP leaks and misconfigured protocols, showing real user IPv4 addresses despite the app indicating an active connection.
- The initial patch failed to stop IPv6 address leaks across proprietary protocols like Lepus and LinkSentinel, as well as OpenVPN connections.
- Following additional technical evidence, the company deployed version 3.7.0.0, which testing confirms now successfully blocks unencrypted IPv6 traffic.
- During the update process, the V2Ray protocol was quietly removed, with the provider stating it is still investigating the protocol's status.
Turbo VPN, a widely used virtual private network service owned by Singapore-based Innovative Connecting Pte. Limited, has deployed emergency software updates for its Windows client following the discovery of critical privacy vulnerabilities. The intervention comes after independent technical evaluations exposed active IP leaks and misconfigured protocols that left user traffic unencrypted and exposed.
During recent testing on an IPv4-only connection, investigators observed that real user IP addresses remained visible despite the application interface displaying a successful connection status. Although the provider initially attempted to resolve the issue, subsequent testing revealed that version 3.6.0.0 continued to leak IPv6 addresses across standard OpenVPN connections and proprietary protocols including Lepus and LinkSentinel.
In response to further technical findings, Turbo VPN released version 3.7.0.0 for Windows. Follow-up verification confirmed that this latest build successfully halts unencrypted IPv6 traffic. Meanwhile, questions persist regarding the app's underlying architecture, as the V2Ray protocol was quietly removed during the patch cycle. When questioned about the removal, the company stated that it is still reviewing the protocol.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.