Chrome will now attempt all web platform connections over HTTPS as Google moves to make its browser secure by default.
The new rules will come into effect with Chrome 154, which will be released in October 2026, which will see the browser automatically use the Always Use Secure Connections feature.
The browser will ask for confirmation from a user to visit any public site that does not support HTTPS prior to visiting the webpage.
Despite more and more platforms turning to HTTPS, some websites still use HTTP, which potentially exposes the sites to malicious actors and content.
Driving the change is some of Chrome’s own research into the uptick of encrypted browsing.
Google’s HTTPS Transparency Report revealed that in 2020, 94-99% of Chrome traffic used HTTPS, up from just 30-45% in 2015.
However, after 2020, HTTPS adoption appears to have slumped, with a few holdouts creating security issues.
Further, HTTPS is less prevalent on sites accessed on mobile devices, which can be problematic as web traffic from mobile browsers increases.
Google did admit that many technical and political challenges stand in the way of all platforms achieving full encryption.
Certain countries and regions degrade or even block HTTPS traffic, while some companies and organisations lack the technical resources required to implement HTTPS.
The rollout will see Chrome warning users upon visits to new or rarely visited pages that do not employ HTTPS, and will aim to avoid prompting users when they enter sites they often visit.
Recommended reading
- CMA Investigates Apple and Google Mobile Ecosystems
- Perplexity AI Makes $34.5bn Bid for Google Chrome
- European Commission Accuses Apple of Breaching Digital Markets Act
The rollout will begin initially in April 2026, where Chrome 147 will enable the feature for users already using Enhanced Safe Browsing, which includes over a billion people. Then in October 2026, the feature will be rolled out to all users via Chrome 154.
The warnings will apply to public websites and will exclude internal addresses – these typically carry less risk, and are more difficult to secure with encryption.
In early experimentation, Google found that less than 3% of traffic prompted a warning, with more users issued less than one warning a week.
“In the future, we hope to work to further reduce barriers to the adoption of HTTPS, especially for local network sites. This work will hopefully enable even more robust HTTP protections down the road,” the Chrome team said.





