Cloudflare One Client for macOS (version 2026.8.2100.0)
A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.
This release includes the following highlights:
- Traffic to split tunnel excluded resources is no longer briefly blocked while the client is connecting or reconnecting. The client now keeps its learned split tunnel configuration across reconnects.
- Support for routing non-RFC 1918 local IPv4 networks through the tunnel when unrestricted LAN inclusion is enabled by policy or MDM.
- Faster connects and lower memory use. The hosts file is now read once and shared across the client’s DNS resolvers instead of being reloaded by each one.
Additional changes and improvements
- Improved reauthentication reliability and fixed an issue where a reauthentication could force a new registration.
- Improved client reaction to the current network lowering its MTU.
- Improved DNS reliability on networks with lower MTUs by clamping the TCP maximum segment size (MSS) for DNS-over-HTTPS connections sent through the tunnel.
- Individual DNS-over-HTTPS queries now time out instead of hanging when the upstream server stops responding.
- Improved API reliability by retrying requests dropped when reusing pooled connections.
- Added an MDM setting to prefer IPv4 when resolving hostnames in proxy mode. The setting is off by default.
- Fixed the client reconnecting while Emergency Disconnect was active after switching organizations or re-registering.
- Fixed the client being unable to connect after an upgrade when its stored registration credentials no longer matched its configuration.
- Fixed the client service restarting unexpectedly when it was slow to respond, such as after waking from sleep.
- Fixed Extra Logging failing to capture packets across all interfaces.
- Fixed an issue that could prevent remote diagnostics from completing.
- Fixed DNS connectivity checks failing on IPv6-only networks.
- Fixed the client service exiting when its route-monitoring socket was closed after sleep or wake.
- Fixed DNS enforcement checks making the client service unresponsive on systems with large routing tables.
- Fixed slow captive portal checks causing the client service to become unresponsive or restart while connecting.
- Fixed a race when switching tunnel protocols during key rotation that could prevent WireGuard from connecting.
- Fixed the client continuing to report “No network” after a successful manual disconnect.
- Fixed a client UI crash that could occur when the daemon connection was reset during an IPC request.
- Fixed a startup crash when date formatting data for the system locale had not yet loaded.
Known issues
- None
