CYBER DELTA FORCESearch

HTTPS by default

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”.

CDF News DeskGoogle Security Blog28 Oct 2025, 10:31 pm
CDF REPORT

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”.

This means Chrome will ask for the user's permission before the first access to any public site without HTTPS.

The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS Chrome Security's mission is to make it safe to click on links.

That gives users no opportunity to see Chrome's "Not Secure" URL bar warnings after the risk has occurred, and no opportunity to keep themselves safe in the first place.

When links don't use HTTPS, an attacker can hijack the navigation and force Chrome users to load arbitrary, attacker-controlled resources, and expose the user to malware, targeted exploitation, or social engineering attacks.

In this mode, Chrome attempts every connection over HTTPS, and shows a bypassable warning to the user if HTTPS is unavailable.

Since HTTP navigations remain a regular occurrence for most Chrome users, a naive approach to warning on all HTTP navigations would be quite disruptive.

One way we're balancing risks to users is by making sure Chrome does not warn about the same sites excessively.

We will enable the "Always Use Secure Connections" setting in its public-sites variant by default in October 2026, with the release of Chrome 154.

IT professionals may find it useful to read our more resources to better understand the circumstances where warnings will be shown, how to mitigate them, and how organizations that manage Chrome clients (like enterprises or educational institutions) can ensure that Chrome shows the right warnings to meet those organizations' needs.

What you need to know

Since HTTP navigations remain a regular occurrence for most Chrome users, a naive approach to warning on all HTTP navigations would be quite disruptive.

One way we're balancing risks to users is by making sure Chrome does not warn about the same sites excessively.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Three Ukrainians to face charges for alleged hack of 610,000 Roblox accountsThe Record · 16 Sept 2026, 8:00 pmCenterPoint Energy Tells SEC Customer Data Was Stolen After 7.5Mn Records Advertised OnlineThe Cyber Express · 16 Sept 2026, 3:27 pmWho’s Tracking You? Use This New Service to Find OutKrebsOnSecurity · 14 Aug 2026, 4:54 pmRead This Before You Buy That TV Streaming StickKrebsOnSecurity · 30 Jul 2026, 10:19 pm