There are multiple online services and JavaScript code available which uses WebRTC function. Even if you are using VPNs or Privacy based browsers it leaks your actual public and private IP address. This is more of a privacy issue rather than security if we talk specifically in browser-based bug bounty, however, such information can help an attacker to do further recon/attack if they are in the same network. The Android security team has conducted an initial severity assessment on this report, but determined the information being leaked is not sensitive enough to warrant a bounty.”]
Source: https://securityaffairs.co/wordpress/70941/hacking/webrtc-ip-leakage.html