Google announced that starting with Chrome version 154, the browser will default to using secure HTTPS connections for all public websites, warning users before they access any site that does not support HTTPS. This change is part of the new 'Always Use Secure Connections' feature, which aims to make secure browsing the standard and will require user approval before opening insecure HTTP sites. Internal addresses such as routers, intranets, and servers will be exempt from these warnings due to their lower risk profile.
The rollout will begin in April 2026 with Chrome 147 for Enhanced Safe Browsing users and expand globally in October 2026. Google cited the significant increase in HTTPS adoption, from 30-45% of Chrome traffic in 2015 to 95-99% by 2020, as a key factor enabling this shift. Early testing indicated that fewer than 3% of visits triggered warnings, suggesting most sites are already compliant. Google plans to further reduce barriers to HTTPS adoption, especially for local network sites, to enhance user security against potential attackers exploiting insecure connections.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Reports said Google plans to automatically block unsecured sites in Chrome starting in 2026, expanding enforcement beyond warnings for HTTP pages. This reflects a broader move to phase out insecure web connections in the browser.
Google said Chrome 154 will default to the 'Always Use Secure Connections' setting, warning users before they visit insecure HTTP sites. The change was reported as a major browser security shift affecting how Chrome handles non-HTTPS connections.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.