Google announced that starting with Chrome version 154, scheduled for release in October 2026, the browser will by default warn users before connecting to public websites that do not use HTTPS. This change will enable the 'Always Use Secure Connections' setting for all users, requiring explicit user permission before accessing any public site over unencrypted HTTP. The move aims to protect users from man-in-the-middle attacks, data interception, and other risks associated with insecure HTTP connections. Chrome will display warnings primarily when users attempt to visit new or rarely accessed sites that lack HTTPS, rather than repeatedly alerting users for frequently visited insecure sites.
This update builds on Chrome's existing HTTPS-First Mode, which has been available as an opt-in feature since 2021. Users will also have the flexibility to enable insecure connection alerts for both public and private sites, including enterprise intranets. The initiative is part of a broader industry push to promote secure web browsing and raise awareness about the importance of HTTPS, as highlighted during Cybersecurity Awareness Month. Security education efforts, such as those by ManageEngine, continue to emphasize the critical role of HTTPS in protecting user data and preventing exploitation by attackers.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A SecuritySenses post for Cybersecurity Awareness Month highlighted HTTPS and its role in web security awareness. This reflects public-facing educational messaging about secure web connections.
BleepingComputer reported that Google Chrome will warn users before they open insecure HTTP sites, marking a browser security change aimed at discouraging unencrypted web access. The reference indicates this development was public by the article's publication date.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.