Google Chrome's new post-quantum cryptography may break TLS connections
ID: d67cdd20-9bff-5504-84fd-ca315502ceef
STIX ID: report--d67cdd20-9bff-5504-84fd-ca315502ceef
Feed Name: Bleeping Computer
Chrome 124 (and Edge 124) enables a hybrid post-quantum TLS key exchange (X25519Kyber768) by default, exposing interoperability bugs in some servers, firewalls, and middleboxes that cannot handle larger TLS ClientHello messages—leading to connection resets and SSL handshake failures. Google clarifies this is not a browser bug but non-compliant TLS implementations; affected users and admins can temporarily disable the Kyber feature via chrome://flags/#enable-tls13-kyber or enterprise/group policies while vendors update their systems, with the caveat that post-quantum secure ciphers will be required in the future.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
