megachangelog
Feature1.68.0

Tailscale v1.68.0

Tailscale 1.68.0 introduces auto-updates for containers, improved startup reliability across platforms when other VPN apps are present, and adds macOS CLI integration and Taildrop notifications. The release includes security improvements like TunnelVision vulnerability warnings, platform-specific fixes for DNS handling, exit node behavior, and various UI and stability improvements across iOS, Android, tvOS, and Windows.

All Platforms
  • New: Auto-updates are available for containers. The tailnet-wide default is ignored in containers.
  • New: When enabled, auto-updates get applied even if the node is down or disconnected from the coordination server.
  • Changed: tailscale lock status now prints the node's signature.
  • Changed: Go is updated to version 1.22.4.
Windows
  • Changed: .exe installer no longer downloads MSI packages for Windows 7 and Windows 8, automatically. See the v1.42.0 changelog for our initial end of life announcement.
macOS
  • New: Standalone variant of the client can now install a launcher for the Tailscale CLI in /usr/local/bin by going to Settings, CLI integration, then Show me how.
  • New: Standalone variant of the client now supports notifications when a file is received using Taildrop.
  • New: Pop-up notification displays when a network might be vulnerable to a potential TunnelVision attack. For more information, see TunnelVision vulnerability and Tailscale.
  • Changed: Client starts up more reliably if another VPN app is running when Tailscale is enabled.
  • Changed: .pkg installer terminates pre-existing copies of Tailscale and the VPN extension before proceeding with installation if Tailscale was already installed.
  • Fixed: TunnelBear installation is properly detected, and warns the user about incompatibility.
  • Fixed: Using Exit Node label no longer appears incorrectly in the app menu before completing onboarding, upon the first time app launch.
  • Fixed: Fixed a bug with split DNS domains being used as search domains after a network change.
iOS
  • Changed: Battery life is optimized by offloading DNS resolution to iOS in more cases.
  • Changed: Client now starts more reliably if another VPN app is running when Tailscale is enabled.
  • Fixed: Bug report view no longer copies the bug report ID to the clipboard automatically.
  • Fixed: Reauthenticate button for in-app key expiry notifications works as expected.
  • Fixed: Dark mode contains minor changes to UI colors.
  • Fixed: Fixed a bug with split DNS domains being used as search domains after a network change.
tvOS
  • Changed: Client now starts more reliably if another VPN app is running when Tailscale is enabled.
  • Fixed: Reauthenticate button for in-app key expiry notifications works as expected.
Android
  • Changed: On-off toggle state better matches the actual client state.
  • Changed: Status notifications when Tailscale is disconnected are now background notifications, and tapping on notifications launches the Tailscale app.
  • Changed: Client starts automatically after the first login.
  • Changed: System policy (MDM) support is added for mandatory exit nodes.
  • Fixed: Organization name is now rendered properly when set in the ManagedByOrganizationName system policy.
  • Fixed: Crashing no longer occurs when launching Tailscale and another VPN application was already running.
  • Fixed: Running an exit node no longer lets you use another device as an exit node and vice versa.
  • Fixed: Home screen shows the selected exit node country and city when using Mullvad exit nodes.

Note: The Tailscale client releases for containers such as the Kubernetes operator, Docker image, and tsrecorder are typically released a few days after the initial client release. A separate changelog will be published when client updates for containers are available.

containersauto-updatesvpnmacosandroidiosdnsexit-nodes

Source: original entry ↗

More from Tailscale

Follow Tailscale to get its new changes in your feed and email digest.

Improvement1.104.1

Tailscale v1.104.1 — Performance and Features Release

Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.

performancememorywireguardfeaturesmulti-platform
Feature

Declarative node sharing

Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.

node-sharingpolicysecuritymulti-tailnetaccess-control
Fix1.102.5

Linux client reconnection stability fix

Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.

linuxstabilityreconnection
See all Tailscale changes →