Mullvad VPN disclosed a fingerprinting vulnerability in May 2026 that could allow a website to link a user’s activity across different Mullvad servers, undermining the specific privacy benefit of switching servers to separate sessions. An independent security researcher flagged the issue on May 15, and Mullvad acknowledged it and published a technical breakdown within days, a response speed worth noting given how the story ends.
What the flaw actually does
Mullvad assigns each connecting device an exit IP address from a range available on the server it connects to. According to Mullvad’s own writeup and reporting by Tom’s Guide, that assignment is not random: a device’s relative position within one server’s IP range carries over to roughly the same relative position on a different server. If a device lands at the 40th percentile of Server A’s address range, it will land at approximately the same percentile on Server B.
A website observing a user’s traffic on two different Mullvad servers could use this consistent positioning to infer that both sessions came from the same device, without needing a cookie, a login, or the user’s real IP address at any point. The flaw does not expose a user’s identity or real IP. It defeats the specific expectation that switching servers creates a clean break between sessions.
Why Mullvad’s own architecture created the opening
Most VPN providers assign a single shared exit IP per server. Mullvad instead operates a range of exit addresses per server specifically to reduce overcrowding on any single IP and avoid mass blacklisting by streaming and anti-fraud systems. That design choice, intended as a privacy and reliability improvement, is what made consistent positional assignment possible in the first place, since the underlying method for allocating an address within the range remained predictable across servers.
Mullvad’s response
Mullvad confirmed the issue publicly within days of the researcher’s disclosure and published a full technical explanation on its blog, along with an interim mitigation users could apply immediately: logging out of the app, logging back in, and reconnecting regenerates the device’s WireGuard key, which breaks the positional pattern that made the fingerprinting possible.
A permanent, server-side fix has been rolling out since the disclosure and does not require an app update on the user’s end. Mullvad has kept a status page updated as servers are patched.
What Mullvad users should actually do
For most users, this flaw doesn’t require any action, it only matters if you specifically switch servers with the intent of separating your online activity into unlinkable sessions. If that’s part of how you use Mullvad, the interim fix is straightforward: open the app, log out, log back in, then connect to your new server. This regenerates your key and resets the pattern before you start a fresh session.
How this affects Mullvad’s standing on privacy
Mullvad has one of the stronger privacy reputations in the industry, built on no-account-email signup, cash and cryptocurrency payment options, and a no-logs policy that held up when Swedish police raided its offices in 2023 and found nothing to seize. This flaw doesn’t change any of that underlying architecture. What it does show is that even providers with genuinely strong privacy defaults can have subtle implementation issues that only surface under close, independent scrutiny, and that Mullvad’s response (rapid acknowledgment, public technical detail, and an immediate user-facing workaround) is close to the standard you’d want from any provider handling a disclosure like this.
How this compares to fingerprinting risks in general
It’s worth putting this flaw in context alongside the broader fingerprinting problem every VPN user faces regardless of provider. Even with this specific issue fixed, no VPN, Mullvad included, protects against browser-level fingerprinting: the collection of font lists, screen resolution, and canvas rendering data that can identify a device independent of its IP address entirely. The Mullvad flaw was a network-layer issue specific to exit IP assignment; browser fingerprinting is a separate, unrelated layer that no VPN on the market fully solves on its own. See our full explainer on browser fingerprinting for what a VPN can and can’t cover here, since conflating the two is an easy mistake to make after a story like this one.
How independent disclosure is supposed to work, and why it worked here
Responsible disclosure means a researcher privately notifies the affected company before publishing details publicly, giving the company a window to fix the issue or at least prepare a mitigation before attackers or curious third parties can act on the same information. That’s what happened here: the researcher notified Mullvad, Mullvad confirmed and began work on a fix, and only then did the technical details become public, alongside Mullvad’s own explanation rather than solely through outside reporting. This sequencing matters because it means Mullvad’s users learned about both the problem and an immediate workaround at the same time, rather than the vulnerability circulating publicly while the company scrambled to catch up. It’s also a useful reminder that a VPN provider having a disclosed vulnerability at all isn’t automatically disqualifying, how the provider responds afterward tells you more about its trustworthiness than the mere existence of the issue.
The disclosure timeline
- May 15, 2026: An independent security researcher privately flags the exit-IP fingerprinting issue to Mullvad
- May 20, 2026: Mullvad publicly acknowledges the issue and confirms a fix is in testing
- May 21, 2026: Tom’s Guide and other outlets report on the disclosure, along with Mullvad’s published technical breakdown and interim mitigation steps
- Ongoing through mid-2026: Mullvad rolls out the permanent, server-side fix gradually across its network, tracked on its public mitigation status page
How this fits into Mullvad’s broader track record
This isn’t Mullvad’s first brush with public scrutiny, and it has generally handled it well. When Swedish police raided its Gothenburg office in 2023 looking for user data tied to a criminal investigation, Mullvad’s no-logs architecture meant there was nothing to hand over, an outcome that did more for its credibility than any marketing claim could have. The fingerprinting disclosure fits the same pattern: a real issue, found by an outsider, acknowledged quickly, and fixed at the infrastructure level without requiring Mullvad’s user base to just take the company’s word for it that everything’s fine.
Should this change which VPN you use?
Not on its own. The flaw was disclosed responsibly, fixed at the infrastructure level without requiring user action beyond the temporary workaround, and doesn’t expose real identities or IP addresses. It’s a reminder that no VPN’s privacy claims should be taken purely on trust, independent audits and public vulnerability disclosures like this one are exactly the mechanism that surfaces issues like this rather than leaving them undiscovered. See our Mullvad review for how it stacks up overall, flaw notwithstanding.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Mullvad's exit-IP fingerprinting flaw was real but narrow in scope: it doesn't expose identities or IP addresses, only the ability to link sessions across servers for users who specifically rely on server-switching for separation. Mullvad's fast disclosure and rollout of a permanent fix is a reasonable response, and the interim log-out-and-back-in workaround closes the gap immediately for anyone who needs it now.
Keep reading: Mullvad VPN Review 2026 and Does a VPN Protect You From Browser Fingerprinting?.