Open-source project
mullvad/mullvad-browser avatar
mullvad/mullvad-browser

Mullvad Browser: a Tor Browser without the Tor Network

Privacy-focused browser for Linux, macOS and Windows. Made in collaboration between @torproject and @mullvad

2,573 stars69 forksShellLicense varies

At a glance

What is it?
Mullvad Browser is a Firefox-based privacy browser built by Mullvad VPN and the Tor Project, aimed at users who want Tor Browser's anti-fingerprinting defaults but route traffic through a VPN instead of onion routing. The main branch of the repository holds only a README and a scripts directory, so the real source lives in tagged branches and on the Tor Project GitLab.
Who is it for?
Adopt Mullvad Browser if you already trust a VPN provider and want Tor Browser's fingerprinting defenses without onion routing, and you accept that Linux builds are 64-bit only, Windows needs 10 or later, and macOS needs Sonoma (14) or later. Do not adopt it if you need a mobile build or a browser you can extend with arbitrary add-ons, because the README lists no Android or iOS package and the whole design assumes a uniform browser fingerprint.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Shell, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Mullvad Browser is for, and who it is not for

Mullvad Browser is a privacy-focused web browser developed in a collaboration between Mullvad VPN and the Tor Project. The README describes it plainly: it is designed to minimize tracking and fingerprinting, and you could say it is a Tor Browser to use without the Tor Network. Instead, you route it through a trustworthy VPN. That sentence is the whole product thesis. Tor Browser hides your traffic inside the onion network; Mullvad Browser keeps Tor Browser's client-side defenses and moves the network-trust problem to your VPN provider.

The audience follows from that. If you already pay for a VPN and want the browser-level protections that usually come bundled with Tor Browser, this is aimed at you. If you want anonymity against a global adversary, it is not: a VPN sees your traffic origin in a way that Tor's three-hop circuit does not. The README frames the goal as providing one more alternative beside the Tor Network to browse with more privacy, not as a replacement for it. That distinction matters when you decide which one to install.

How the Tor Project codebase is packaged here

The architecture is easiest to read from the repository layout rather than from the README. The main branch contains three top-level entries: .github/, README.md, and scripts/. The README states directly that this main branch only contains the Readme, and that source code is obtained by going to specific branches and/or tags. It also points to the Tor Project GitLab at gitlab.torproject.org/tpo/applications/mullvad-browser.

So the build is a downstream of Tor Browser. The README's build instructions do not describe a Mullvad-specific toolchain at all; they say to follow the instructions from the Tor Browser building guide. In practice that means the browser is assembled from the Tor Browser source tree with Mullvad's branding and configuration layered on, and the scripts/ directory in this repository holds the automation that does the layering. If you want to audit what actually ships, reading this repository's main branch will not tell you. You need the tags and the GitLab mirror. That is a real friction point for anyone doing a source review before installing.

Installing Mullvad Browser and verifying the download

The README does not give a package-manager command. It says to visit the download page at mullvad.net/download/browser to get the latest stable release, and notes that .deb and .rpm packages are available for Linux through the project's repositories at mullvad.net/en/download/browser/linux. There is no apt or dnf line in the README, so treat the download page as the source of truth for repository setup rather than copying a command from a third party.

Supported platforms are stated precisely: Linux 64-bit only, Windows 10 or later 64-bit only, and macOS Sonoma (14) or later. If your machine falls outside that, the README offers nothing.

Mullvad Browser is signed by the Tor Browser Developers. The README does not include the verification commands inline; it links to a separate guide. The relevant page is:

bash
# The README points to this guide rather than listing the commands:
# https://mullvad.net/en/help/verifying-mullvad-browser-signature/

Follow that guide before you run the installer. Because the signing key belongs to the Tor Browser Developers rather than to Mullvad alone, a valid signature tells you the artifact came through the same release pipeline as Tor Browser, which is the property you actually want to confirm.

For a first real use, the interesting check is not that the browser opens. It is that the fingerprinting defenses are active by default. Open the browser, and without changing any settings, confirm that the default window size and user agent are the ones the project ships, since the protection depends on every user looking identical. Feedback and bug reports go to the issue tracker in this repository or to [email protected].

The fingerprinting trade-off you have to accept

A browser that minimizes fingerprinting has to make everyone look the same. That is the mechanism, and it is also the limitation. The README's stated purpose is to minimize tracking and fingerprinting, which in a Firefox-derived browser generally means resisting the per-user variation that extensions, custom fonts, odd window sizes and modified settings introduce.

The practical consequence is that Mullvad Browser is a poor fit for people who treat a browser as a workbench. If your workflow depends on a large set of extensions, or on a specific window geometry, you are working against the design. The related search interest in a Mullvad Browser extension reflects a real expectation that users bring their own add-ons; the README says nothing about an extension ecosystem, and its emphasis on a uniform fingerprint points the other way. Treat any add-on you install as something that makes you more distinguishable, not less.

The second limitation is coverage. The README lists Linux, Windows and macOS only. It does not document an Android or iOS build. Searches for Mullvad Browser on Android, an Android APK, or Mullvad Browser Mobile have no answer in this repository, and the absence is worth taking at face value: the project documents desktop platforms and nothing else. If mobile is a requirement, this is the wrong tool today.

Mullvad Browser compared with Brave

The obvious comparison, and one people search for, is Mullvad Browser versus Brave. The difference is philosophical before it is technical. Brave is a Chromium-based browser that ships its own ad and tracker blocking and its own optional rewards and crypto features; it is a product with a business model attached. Mullvad Browser is a Firefox-derived browser built by a VPN company and the Tor Project, and its stated goal is minimizing tracking and fingerprinting rather than blocking ads as a feature.

That shapes what you get. Brave's protections are largely per-site and configurable, and it expects you to customize. Mullvad Browser's protections are meant to be uniform, which is why the README frames it as a Tor Browser without the Tor Network. If you want a browser you tune, Brave is the more natural fit. If you want one where the defaults are the protection and tuning is a liability, Mullvad Browser is the more coherent choice. Neither is a superset of the other, and the README makes no claim about ad blocking at all.

Licence, maintenance and what an upgrade costs you

The README states the project is licensed under the Mozilla Public License V2. MPL-2.0 is a file-level copyleft licence: modifications to covered files must be made available under the same licence, while larger works that combine MPL files with other code can be distributed under other terms. If you are only downloading and running the browser, that distinction does not change your obligations. If you fork it or ship it inside a product, read the licence text rather than relying on a summary, and get proper advice if the stakes are commercial.

On maintenance, the repository facts are the useful signal. The last push to this repository was on 2026-09-21, and the most recent releases listed are 16.0a12 on 2026-09-22, 15.0.23 on 2026-09-21, and 16.0a11 on 2026-09-03. The repository is not archived. The release cadence shows a stable line and an alpha line running in parallel, which is what you would expect from a project tracking upstream Firefox security fixes.

Upgrade cost is where the packaging decision bites. Because the build follows the Tor Browser building guide and the source lives in tags rather than on main, self-building means tracking two upstreams: Tor Browser's build system and Firefox's release train. For most users the .deb and .rpm repositories are the sane path, and the cost is simply staying current, since a privacy browser that lags on security patches is worse than a mainstream one.

Editorial conclusion

Adopt Mullvad Browser if you already trust a VPN provider and want Tor Browser's fingerprinting defenses without onion routing, and you accept that Linux builds are 64-bit only, Windows needs 10 or later, and macOS needs Sonoma (14) or later. Do not adopt it if you need a mobile build or a browser you can extend with arbitrary add-ons, because the README lists no Android or iOS package and the whole design assumes a uniform browser fingerprint. Before installing, verify the download against the Tor Browser Developers signature using the guide at mullvad.net/en/help/verifying-mullvad-browser-signature, and check that the .deb or .rpm repository matches your distribution.

Frequently asked questions

Is Mullvad Browser free?

The README does not describe a price, and it directs users to a download page for the latest stable release. It does not state that a Mullvad VPN subscription is required to download or run the browser, though the README's framing assumes you pair it with a trustworthy VPN.

How do I install Mullvad Browser on Linux?

The README says to get the release from the download page at mullvad.net/download/browser, and that .deb and .rpm packages are available for Linux through the project's repositories at mullvad.net/en/download/browser/linux. It does not list per-distribution install commands, so use the repository page for your distribution rather than a copied command.

Is Mullvad Browser safe to use?

The README describes it as designed to minimize tracking and fingerprinting, built in collaboration between Mullvad VPN and the Tor Project, and signed by the Tor Browser Developers. It does not make an anonymity claim, and it positions the browser as an alternative to the Tor Network rather than a substitute for it.

Does Mullvad Browser work with extensions?

The README does not document an extension policy or an add-on ecosystem. Its stated purpose is minimizing tracking and fingerprinting, and the repository README offers no guidance on which add-ons are compatible.

Is Mullvad a good browser?

The README positions it as a Tor Browser to use without the Tor Network, built to minimize tracking and fingerprinting and meant to be paired with a trustworthy VPN. Whether that trade-off suits you depends on whether you want uniform defaults rather than a browser you customize heavily.

Official sources

  1. Issues
  2. mullvad/mullvad-browser on GitHub
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/mullvad-mullvad-browser.svg)](https://hysenlabs.com/projects/mullvad-mullvad-browser)