No, any website can detect your local IP address, then use ajax to scan a targeted IP subnet range fairly quickly (and completely hidden from the user) to find any shitty CORS-enabled web interface your company has (think some "modern" internal accounting webapp that enables CORS for its "API").
Prior to WebRTC you'd have to scan much larger IP ranges to try and find internal network webapps that are CORS enabled.
Prior to WebRTC you'd have to scan much larger IP ranges to try and find internal network webapps that are CORS enabled.