logo

HTTPS by default

ID: 2eb43139-9c39-5cb4-b506-e1326537f181

STIX ID: report--2eb43139-9c39-5cb4-b506-e1326537f181

Feed Name: Google Online Security Blog

Date Published: 2025-10-28

Date Updated: 2026-04-27

Author: Google

...
...

Google’s Chrome Security team announces that Chrome 154 (Oct 2026) will enable "Always Use Secure Connections" by default in its public-sites variant, attempting HTTPS first and showing a bypassable warning on new or infrequently visited public HTTP sites; experiments in Chrome 141 indicate low warning volumes, and the feature will first roll out to Enhanced Safe Browsing users in Chrome 147 (Apr 2026). The change excludes private/local sites to reduce noise, leverages a new local network access permission to unblock HTTPS migrations, and urges developers and IT admins to enable the setting now to identify and remediate remaining HTTP usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.