Disabling WebRTC entirely trades away real calling and collaboration functionality — worth trying safer, narrower fixes first, and reserving full disablement for cases where nothing else resolves a confirmed leak.
WebRTC and a VPN operate at different layers and serve different purposes — one is a communications API, the other a network tunnel — which is exactly why they can interact badly rather than compete as alternatives.
Seeing a private, local-range address in a WebRTC candidate list is normal and not a public exposure — those addresses only mean anything on your own local network, and modern browsers mask them further with mDNS.