Skip to content

Chrome 154 starts asking before it opens any public HTTP site, and old bookmarks will feel it first

Chrome 154 HTTP Warning: Always Use Secure Connections

Chrome 154 reached the Stable channel on October 1, 2026, and Google’s plan for this release is to turn on “Always Use Secure Connections” by default. In practice, that means a Chrome HTTP warning appears before the browser first opens any public site that does not use HTTPS. Most of the web will never trigger it. The pages that will are the forgotten bookmark, the old forum, and the small business site that stopped renewing its certificate, which are also the places where someone on public Wi-Fi has the easiest job.

TL;DR: Google’s security team says Chrome 154 enables Always Use Secure Connections for all users, so Chrome asks before first loading a public site without HTTPS. You can choose Continue to site or Return, and you can switch the setting off at chrome://settings/security. Private addresses such as local IPs and intranets are exempt. Google’s own data suggests most people will see fewer than one prompt a week.

What the Chrome HTTP warning does in Chrome 154

Chrome 154 asks for permission before the first access to any public site without HTTPS, according to Google’s Chrome security post. The dialog says the site does not support a secure connection and that attackers could view or change information.

You get two buttons, Continue to site and Return. Pick the first and the page loads the way it always did.

The setting is not brand new. It reached more than 1 billion users with Enhanced Safe Browsing turned on in Chrome 147 in April 2026, and Chrome 154 extends it to everyone. Chrome also moved to a two-week release cycle starting with Chrome 153, so changes like this reach people faster than the old four week rhythm.

ItemDetail
Chrome 147, April 2026Enabled for users with Enhanced Safe Browsing, more than 1 billion people
Chrome 154, October 2026Enabled by default for all Chrome users
Stable build, October 1, 2026154.0.8037.97/.98 on Windows and Mac, 154.0.8037.97 on Linux
Setting nameAlways Use Secure Connections
Where to change itchrome://settings/security
ExemptPrivate sites such as local IPs, single label hostnames, and intranets

The more interesting question is who actually gets stopped.

Who will actually see the Chrome HTTP warning

Very few people, if Google’s numbers hold. The same post puts HTTPS adoption between 95% and 99% across platforms, and for public sites Linux sits at 97%, Windows at 98%, and Android and Mac above 99%.

Google also says the median user sees fewer than one warning a week, and the 95th percentile sees fewer than three.

Picture opening a recipe blog you bookmarked in 2014. The page still loads over plain HTTP, Chrome stops first, and you decide whether the recipe is worth the click. That is a small speed bump in exchange for a safer default, and for most people it will be invisible until the one old link that is not.

Not every address on your network gets the same treatment, though.

What Chrome leaves alone

Private sites are exempt from the default prompt, including local IP addresses, single label hostnames, and corporate intranets. Google’s stated reason is that “private names can refer to different hosts on different networks,” so a public certificate cannot vouch for them.

Your router page at a local address and the NAS in the closet keep loading as before. Only public sites trigger the dialog.

If you run a small site, the practical test is to open it in Chrome 154 and see what happens. A prompt in front of your own homepage shows you what a visitor sees.

Whether the prompt shows up on your machine is a separate question from whether Chrome supports it.

How to check the setting on your own browser

Open Chrome, go to chrome://settings/security, and look for Always Use Secure Connections. With the toggle on, you get the prompt. Turn it off and Chrome goes back to loading HTTP pages without asking.

Switching it off is a poor trade on a laptop that joins hotel and cafe Wi-Fi, which is where plain HTTP pages are easiest to tamper with. If you are weighing wider privacy trade-offs in the browser, our explainer on browser fingerprinting covers a different kind of tracking that this prompt does not touch.

One caveat on timing. The Chrome Releases post says the Stable update will roll out over the coming days and weeks, so the prompt may not appear the day you update. Google’s security post remains the source for the default.

The same update carries 11 security fixes, one of them rated critical, which is reason enough to update either way.

Leave a Reply

Your email address will not be published. Required fields are marked *