Version 2.24 build 12 du 03/09/2026- Added : Custom SNI support for stunnel/wstunnel anti-censorship connections.
- Added : Cross-platform diagnostics for API connectivity login failures so logs can better distinguish DNS, routing, proxy, IPv4/IPv6, and local security-policy failures.
- Added : A SECURITY.md document.
- Improved : The Windows IKEv2 connector. A complete rewrite of the code to improve connection setup speed and connection robustness.
- Improved : Anti-censorship startup and failover by supporting parallel backup domain testing in wsnet.
- Improved : Firewall behavior consistency across platforms and firewall modes.
- Improved : Always On/Always On+ firewall handling with Allow LAN Traffic by disabling risky LAN allowance on mode enable and warning when LAN traffic is explicitly re-enabled.
- Improved : Hardening for elevated executables using Windows process mitigation APIs where applicable.
- Improved : Windows compiler and linker security hardening, including Control Flow Guard and related mitigation settings.
- Improved : Windows build targeting to Windows 10 2004 so newer Windows APIs can be used without changing the minimum install version.
- Improved : CLI-only behavior by automatically watching config file changes instead of requiring windscribe-cli preferences reload.
- Improved : Custom SNI handling by keeping Custom SNI Domain visible/editable independently of the Protocol Tweaks mode, while still applying it only to Stealth/stunnel and WSTunnel connections.
- Improved : wsnet/desktop hardening by validating values received from wsnet and applying wsnet security-audit fixes for URL construction, TLS/network handling, logging, parsing, and failover robustness.
- Improved : DNS leak firewall setup by de-duplicating DNS server entries before adding Windows firewall filters on Windows.
- Improved : Split tunneling so non-tunneled apps can preserve native ISP IPv6 on dual-stack networks while tunneled apps remain leak-protected on Linux.
- Improved : Installer and uninstaller logging on Windows.
- Improved : The ConnectionManager sub-system.
- Improved : WireGuard stale-handshake detection.
- Improved : Connection failed messaging when IKEv2 (RAS) services are unavailable.
- Improved : API retry access to use bounded per-resource exponential back-off, starting at 1 second and doubling to a 5-minute cap with jitter.
- Improved : Belarusian translations in the GUI, installer and CLI from GitHub user dubovy-achvelak.
- Improved : Dependency build integrity by pinning or verifying wstunnel and AmneziaWG prebuilt source dependencies.
- Improved : Logging when modifications to the Windows hosts file fail during IKEv2 connect/disconnect.
- Improved : Objective-C memory management consistency by enabling ARC uniformly across the project.
- Fixed : Local privilege escalation vulnerability caused by SGID helper descriptor reuse and OpenVPN custom config parser differences on Linux.
- Fixed : Local privilege escalation vulnerability caused by OpenVPN inline-parser differences and root-execution-capable directives in custom OpenVPN configs.
- Fixed : Local privilege escalation vulnerability caused by an embedded NULL in a custom config coercing OpenVPN to load a malicious plug-in.
- Fixed : File disclosure vulnerability in the Windows helper.
- Fixed : Insecure OpenVPN management interface behavior that could allow local management-port hijacking, spoofed VPN state, or credential capture.
- Fixed : WireGuard connection mode unavailable when Always On+ firewall mode is enabled and cached WireGuard connection information is available.
- Fixed : c-ares Windows DNS server detection regression that could leave only 127.0.0.1:53 and cause DNS resolution failures.
- Fixed : The Windscribe service getting stuck in the stop pending state when a stop is requested while the desktop app is running on Windows.
- Fixed : A possible crash when enabling Secure Hotspot after connecting the VPN on Windows.
- Fixed : A rare crash when launching at startup before macOS screen information is available.
- Fixed : Allow LAN traffic not applying correctly to IPv6 LAN and multicast traffic while connected on Windows.
- Fixed : Inclusive split tunneling with WireGuard on Windows tunneling non-included traffic through the VPN.
- Fixed : Inclusive split tunneling on Windows blocking native ISP IPv6 for non-included apps on dual-stack networks.
- Fixed : HTTP Proxy settings rejecting valid high port numbers in the 63536-65535 range.
- Fixed : Always On+ firewall mode skipping WireGuard when a valid cached WireGuard config is available.
- Fixed : Always On+ unsecured-network handling disconnecting during WireGuard-to-OpenVPN fallback when no cached WireGuard config is available.
- Fixed : Connected DNS split-DNS reachability to internal RFC1918 DNS servers while the VPN is active.
- Fixed : Cached WireGuard config is not cleared when its keys are invalidated.
- Fixed : OpenVPN adapter creation failure insufficiently reported to the user on Windows.
- Fixed : First click on Rotate IP may not rotate IP.
- Fixed : App startup/shutdown delay when IKEv2 (RAS) services are unavailable on Windows.
- Fixed : CLI-only app is missing a dependency for libbrotli.
- Fixed : Failed captcha treated as something to failover on and retry.
- Fixed : Network name does not refresh after waking on a different network on Windows.
- Fixed : App may get stuck on the logging in screen.
- Fixed : Hashed-login failures caused by user accidentally including leading/trailing whitespace in their input.
- Fixed : Static IP OpenVPN/TCP connections prompting for credentials instead of supplying stored Static IP credentials internally.
- Fixed : Remembered credentials for external .ovpn custom configs not being persisted immediately across restart/reboot.
- Fixed : Account tab Add Email text may overlap when account has no email and language is non-English.
- Fixed : Polish free-data counter text overlapping the upgrade CTA and locations-list chevron.
- Fixed : Help/About->Jobs link referencing stale URL.
- Updated : cURL 8.21, c-ares 1.34.7, OpenVPN 2.7.5, and OpenSSL 4.0.1.
- Updated : WireGuard for Windows to 1.1.