Well, it's a complicated answer, I think.
Generally, it's not an additional risk over how screwed you generally are. If you're taking precautions against existing attacks, then yeah.
Question is, can it be fixed? The WebRTC SDP's for getting a peer-to-peer connection, so the general case seems to need to share IP addresses..
But that's not really needed, if you're normally behind a NAT, you're going to be behind a NAT this time, and don't need to share your real IPs -- just STUN/ICE data. If you're not behind a NAT, they already have your IP address.