2026.4DesktopMobile
Added 2
- Add Ukrainian as a new language in the app
- Aggregate installer-downloader logs by mullvad-problem-report
Changed 3
- Update gotatun to 0.8.1
- Update wireguard-nt to version 1.1 on Windows
- Use arch-specific installers on macOS to deliver updates, making them approximately 50% smaller
Fixed 5
- Align ciphers for custom shadowsocks API access methods between clients and mullvad-daemon, with invalid access methods removed via settings migration
- Fix split tunneling related parse error on macOS 27
- Fix issue where gotatun would fail to start on Linux systems with IPv6 stack disabled
- Fix misleading split tunneling error when offline on Windows
- Fix unhandled error on Windows: Reached the end of the file (os error 38)
Security 2
- Fix management interface socket being created with less restrictive permissions when using MULLVAD_MANAGEMENT_SOCKET_GROUP on Linux and macOS
- Plug hole in Custom DNS firewall rules for LAN resolvers on Linux
From Mullvad VPN
This release is for desktop only.
Here is a list of all changes since last stable release 2026.3:
Added
- Add Ukrainian as a new language in the app.
installer-downloaderlogs are aggregated bymullvad-problem-report.
Changed
- Update
gotatunto 0.8.1.
Windows
- Update
wireguard-ntto version 1.1. This retires the Mullvad fork at https://github.com/mullvad/wireguard-nt.
macOS
- Use arch-specific installers to deliver updates. This makes updates around 50% smaller.
Fixed
- Align ciphers for custom shadowsocks API access methods between clients and
mullvad-daemon. Any existing, invalid access method is removed with a settings migration.
macOS
- Fix split tunneling related parse error on macOS 27.
Linux
- Fix issue where
gotatunwould fail to start on Linux systems where the IPv6 stack had been disabled.
Windows
- Fix misleading "split tunneling" error when offline.
- Fix unhandled error: "Reached the end of the file. (os error 38)"
Security
- Linux and macOS: Fix management interface socket being created with less restrictive permissions
when using
MULLVAD_MANAGEMENT_SOCKET_GROUP. This addresses the advisoryGHSA-p9rr-wc9m-qmwg.
Linux
- Plug hole in Custom DNS firewall rules for LAN resolvers.