logo

Google Chrome's new post-quantum cryptography may break TLS connections

ID: d67cdd20-9bff-5504-84fd-ca315502ceef

STIX ID: report--d67cdd20-9bff-5504-84fd-ca315502ceef

Feed Name: Bleeping Computer

Date Published: 2024-04-28

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Chrome 124 (and Edge 124) enables a hybrid post-quantum TLS key exchange (X25519Kyber768) by default, exposing interoperability bugs in some servers, firewalls, and middleboxes that cannot handle larger TLS ClientHello messages—leading to connection resets and SSL handshake failures. Google clarifies this is not a browser bug but non-compliant TLS implementations; affected users and admins can temporarily disable the Kyber feature via chrome://flags/#enable-tls13-kyber or enterprise/group policies while vendors update their systems, with the caveat that post-quantum secure ciphers will be required in the future.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.