2026.4-beta1Pre-releaseDesktopMobile
Added 2
- Add Ukrainian as a new language in the app
- installer-downloader logs are aggregated by mullvad-problem-report
Changed 3
- Update gotatun to 0.8.1
- Update wireguard-nt to version 1.1
- Use arch-specific installers to deliver updates, making updates around 50% smaller on macOS
Fixed 4
- Align ciphers for custom shadowsocks API access methods between clients and mullvad-daemon, with invalid access methods removed via settings migration
- Fix issue where gotatun would fail to start on Linux systems where the IPv6 stack had been disabled
- Fix misleading split tunneling error when offline on Windows
- Fix unhandled error: Reached the end of the file (os error 38) on Windows
Security 2
- Fix management interface socket being created with less restrictive permissions when using MULLVAD_MANAGEMENT_SOCKET_GROUP on Linux and macOS
- Plug hole in Custom DNS firewall rules for LAN resolvers on Linux
This release is for desktop only.
Here is a list of all changes since last release 2026.3:
Added
- Add Ukrainian as a new language in the app.
installer-downloaderlogs are aggregated bymullvad-problem-report.
Changed
- Update
gotatunto 0.8.1.
Windows
- Update
wireguard-ntto version 1.1. This retires the Mullvad fork at https://github.com/mullvad/wireguard-nt.
macOS
- Use arch-specific installers to deliver updates. This makes updates around 50% smaller.
Fixed
- Align ciphers for custom shadowsocks API access methods between clients and
mullvad-daemon. Any existing, invalid access method is removed with a settings migration.
Linux
- Fix issue where
gotatunwould fail to start on Linux systems where the IPv6 stack had been disabled.
Windows
- Fix misleading "split tunneling" error when offline.
- Fix unhandled error: "Reached the end of the file. (os error 38)"
Security
- Linux and macOS: Fix management interface socket being created with less restrictive permissions
when using
MULLVAD_MANAGEMENT_SOCKET_GROUP. This addresses the advisoryGHSA-p9rr-wc9m-qmwg.
Linux
- Plug hole in Custom DNS firewall rules for LAN resolvers.