megachangelog
Feature1.66.0

Tailscale v1.66.0

Tailscale v1.66.0 introduces client-side quarantining for shared-in exit nodes to mitigate security vulnerability TS-2024-005, stateful filtering for subnet routers on Linux, tab completion for CLI commands, and a new exit-node suggest command. Major updates include Android app rebuild with new UI, improved exit node picking across platforms, auth key login support on iOS and Android, DNS management features, Fast User Switching, and enhanced error detection.

We recommend updating all Tailscale clients to v1.66.0 or later to benefit from additional security improvements.

All platforms
  • New: Implemented client-side quarantining for shared-in exit nodes, as a mitigation for a security vulnerability described in TS-2024-005.
Linux

Note: This change can break existing setups that depend on forwarding connections from external hosts (internet, LAN, Docker containers, and similar) into the tailnet through a Tailscale node. If your setup depends on such forwarding, you can disable stateful filtering with the tailscale up --stateful-filtering=false command.

  • New: Use tab completion to type the first few letters of a Tailscale CLI command, flag, or arguments, followed by the tab key to complete the item being typed. Set up tab completion by using the tailscale completion command.
  • New: Use the tailscale exit-node suggest command to automatically pick an available exit node that is likely to perform best.
  • Changed: Site-to-site networking now also requires --stateful-filtering=false in addition to --snat-subnet-routes=false on new subnet routers. Existing subnet routers with --snat-subnet-routes=false will default to --stateful-filtering=false.
macOS
  • New: View a suggested exit node in the Exit Node picker when available.
  • New: Generate a macOS Configuration Report .txt file from the Bug Report view to help the Tailscale support team diagnose issues.
  • Changed: Improved error detection logic warns the user when a version mismatch is detected between the Tailscale client GUI and the network extension.
iOS
  • New: See direct vs. relayed connections in the Ping view.
  • New: View a suggested exit node in the Exit Node picker when available.
  • New: Use auth keys to log in without using the browser.
  • New: Search tagged devices by tag in the Devices list.
  • New: Remove accounts in the Fast User Switching view by using a long press, without having to log out.
  • Changed: Improved UI experience to log into a custom coordination server like Headscale.
  • Changed: The Fast User Switching view can now be used when Tailscale is disconnected.
  • Changed: Improved error detection logic warns the user when a version mismatch is detected between the Tailscale client GUI and the network extension.
  • Changed: Reduced app launch time.
tvOS
  • New: Manage DNS configuration in the DNS Settings view.
  • New: Generate a bug report identifier by navigating to About Tailscale > Report an issue.
  • Changed: Improved error detection logic warns the user when a version mismatch is detected between the Tailscale client GUI and the network extension.
Android

We've rebuilt the Android app from the ground up, adopting a similar design that we've previously rolled out on iOS and using the latest Android best practices.

  • New: Use new status indicators to see at-a-glance insights into node connectivity. Tap on a node to see detailed information.
  • New: See detailed information about resolvers, domains, and routing configurations in a dedicated DNS Settings view.
  • New: See the status of Tailnet Lock and node keys.
  • New: Use Fast user switching to switch between two or more logged-in accounts on the same device, without requiring you to re-authenticate.
  • New: Use auth keys to log in without using the browser.
  • New: Manage Android devices in your tailnet using Mobile Device Management (MDM) solutions such as Google Workspace, Microsoft Intune, or TinyMDM, among other tools.
  • New: Accessibility support.
  • New: Use dark mode as an alternative to light mode.
  • Changed: The Quick Settings tile has been temporarily disabled, pending resolution of an issue.
  • Changed: More intuitive behavior switching between exit nodes.
  • Fixed: Issue with LAN access during exit node use.
securityexit-nodescliandroidiosdns

Source: original entry ↗

More from Tailscale

Follow Tailscale to get its new changes in your feed and email digest.

Improvement1.104.1

Tailscale v1.104.1 — Performance and Features Release

Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.

performancememorywireguardfeaturesmulti-platform
Feature

Declarative node sharing

Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.

node-sharingpolicysecuritymulti-tailnetaccess-control
Fix1.102.5

Linux client reconnection stability fix

Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.

linuxstabilityreconnection
See all Tailscale changes →