Running a WebRTC leak test and seeing an address like 192.168.1.5 in the results can look alarming at first glance — but this is one of the least concerning things a test can show, not a public location leak.
Why local addresses show up at all
WebRTC's ICE process gathers every candidate address it can, including your device's local network address (a "host candidate") alongside your public one — this is part of how it tries a direct local-network connection first before falling back to a public internet path, which is more efficient when both peers happen to be on the same local network.
Why this isn't a public exposure
Private address ranges (192.168.x.x, 10.x.x.x, and similar — see Public IP vs Private IP) are, by definition, not routable on the public internet. A page seeing your local address learns essentially nothing useful about your actual location or identity from it alone — it only has meaning within your own local network.
How modern browsers handle this further
Many current browsers now mask even this local candidate behind a randomized .local hostname via mDNS, rather than exposing the literal local IP address directly — an additional layer of caution on top of the address already being non-public.
What to actually pay attention to
When reviewing a WebRTC leak test result, focus on public (server-reflexive) candidates specifically — those are the addresses that matter for VPN leak purposes. Local/private candidates are expected, routine, and not evidence of any problem.
FAQ
Should I be concerned if I see multiple local addresses?
No — devices with multiple network interfaces (Wi-Fi and Ethernet simultaneously, for instance) can show multiple local candidates, which is entirely normal.