Exclusive: Turbo VPN releases emergency Windows update after TechRadar uncovers persistent IP leaks

In recent evaluations of Turbo VPN’s Windows client, significant privacy concerns have emerged due to active IP leaks and improperly configured protocols. Owned by Innovative Connecting Pte. Limited, a company based in Singapore, Turbo VPN has achieved over 500 million downloads on Android, a testament to its popularity.

Following our initial technical findings earlier this week, Turbo VPN promptly released a patch. However, version 3.6.0.0 continued to exhibit IPv6 address leaks across its proprietary protocols, Lepus and LinkSentinel, as well as standard OpenVPN connections. In light of further evidence provided by TechRadar, the company has since rolled out a second update, version 3.7.0.0, which effectively addresses the IPv6 leaks. Our testing confirms that this latest iteration successfully blocks unencrypted IPv6 traffic.

Intermittent IP leaks

The primary function of any VPN is to conceal the user’s IP address. However, during our testing of Turbo VPN’s proprietary protocols on an IPv4-only connection, we discovered that our real IP address remained visible. Despite the application indicating a successful connection, all IP lookup tests revealed our actual IPv4 address. We attempted various troubleshooting methods, including rebooting our machine, reinstalling the application, and utilizing multiple independent lookup tools, yet the issue persisted.

To further validate our findings, we installed the app on a second device within a dual-stack IPv4/IPv6 network. This setup revealed a notable flaw: while our IPv4 address was masked, our true IPv6 address was still exposed. Subsequent tests on our IPv4-only connection indicated that while IPv4 masking had stabilized, the initial build’s intermittent nature was evident.

After sharing these technical observations with Turbo VPN, the company issued an update (version 3.6.0.0). Testing this version showed that while IPv4 addresses were consistently masked, IPv6 addresses remained vulnerable across proprietary protocols and standard OpenVPN connections. Given that most modern operating systems and web browsers prioritize IPv6 connections, this oversight left users on dual-stack connections at risk.

With the latest update, the Windows application now effectively blocks unencrypted IPv6 traffic while consistently masking IPv4 addresses.

Lepus: a VPN or Shadowsocks proxy?

Lepus is categorized alongside Turbo VPN’s standard VPN protocols and is touted for its “excellent camouflage with outstanding speed and stability,” particularly in highly restricted networks. However, our initial tests revealed that Lepus functioned differently from conventional VPN protocols. Instead of establishing a system-wide encrypted tunnel, it activated a local ShadowsocksR (ssr.exe) process, modifying Windows settings to run a local proxy on port 46288. This configuration meant that any non-browser data transmitted from the device—such as background OS traffic, desktop messaging applications, and command-line utilities—was not encrypted and instead routed through a standard connection.

We inquired with Turbo VPN regarding the duration of this behavior, but did not receive a specific response. In subsequent tests, version 3.6.0.0 successfully protected all outbound traffic within an encrypted tunnel and operated effectively as a system-wide tunnel for IPv4 traffic. However, the configuration still permitted IPv6 leaks, leaving users on dual-stack connections exposed due to the lack of enabled IPv6 virtual interfaces, assigned IPv6 gateway routes, and firewall rules to block outbound IPv6 traffic.

The official response, and what comes next

After providing multiple rounds of technical feedback to Turbo VPN, the Windows app (version 3.7.0.0) appears to have resolved the remaining IPv6 leak issues. Instead of establishing a comprehensive IPv6 infrastructure, the latest version seems to have implemented IPv6 blocking at the client level, ensuring that all web traffic is directed through the encrypted IPv4 tunnel.

However, detailed information regarding the proprietary protocols remains notably absent within the app and on Turbo VPN’s website. A search for Lepus or LinkSentinel yields no results, and users are left without substantial technical context about how these protocols manage traffic or the security mechanisms they employ. The quiet removal of V2Ray further compounds the lack of clarity, leaving users uncertain about how to best secure their connections.

In response to our initial findings, Turbo VPN stated, “The behavior observed in the Windows client arose only under certain network configurations, appearing to occur in a limited number of network environments.” They added that their technical team conducted a thorough review and implemented necessary improvements in the latest Windows build within a short timeframe. Ongoing testing of the product will continue, with updates to our full review expected in the coming weeks.

Winsage
Exclusive: Turbo VPN releases emergency Windows update after TechRadar uncovers persistent IP leaks