Chrome 155 began rolling out to a small group of Windows and Mac users on September 30, and Google’s beta notes show it adds JPEG XL image decoding, new post-quantum algorithms in WebCrypto, and a way for banks and universities to issue digital credentials into a phone wallet. Most of it is aimed at web developers. The effects still reach you, because they decide how fast photos load, how safely sites handle encryption, and where your digital ID comes from.
TL;DR: Chrome 155 adds JPEG XL decoding using a memory safe Rust decoder, post-quantum algorithms for WebCrypto, and issuance support for digital credentials in mobile wallets. Early stable builds started on September 30, but nothing changes on your screen until sites adopt these tools. Google has not yet published separate stable release notes, so the list below comes from the beta.
What Chrome 155 changes for everyday browsing
Google’s Chrome Releases blog lists version 155.0.8059.26/.27 as an early stable release on Windows and Mac, shared with a small percentage of users on September 30, 2026. The feature list comes from the Chrome 155 beta post published September 16 by Rachel Andrew.
That distinction matters. Beta features can still be held back before a wider rollout, so treat this as what Google intends to ship rather than a final receipt.
| Feature | What it does | Who notices first |
|---|---|---|
| JPEG XL decoding | Decodes image/jxl files with the jxl-rs Rust decoder | Sites that serve photos |
| Post-quantum WebCrypto | Adds ML-KEM, ML-DSA, ChaCha20-Poly1305 and X-Wing | Web app developers |
| Digital Credentials issuance | Lets a site start adding a credential to your wallet | Banks, universities, agencies |
| Hidden iframe audio policy | Lets embedders block audible media in hidden frames | Site owners |
| Module load retry | Allows a failed module to be loaded again with import() | Developers on weak networks |
The rest of this article walks through the three changes that touch ordinary users most.
JPEG XL gives websites a lighter, sharper image format
Chrome 155 adds support for decoding JPEG XL images in Blink using jxl-rs, which Google describes as a memory safe, pure Rust decoder. The format, standardized as ISO/IEC 18181, supports progressive decoding, wide color gamut, HDR, high bit depth and animation.
In practice, a photo heavy page could show a rough version of an image that sharpens as it loads, instead of leaving a blank box while the full file arrives. That only happens once a site actually serves JPEG XL files, so expect a slow start rather than an overnight change.
A decoder written in a memory safe language is the detail most coverage will skip. Image decoders chew through untrusted files from every corner of the web, and that is exactly where Google would want fewer ways for a bad file to cause trouble. It also raises a fair question about how quickly publishers will bother converting their images.
Post-quantum algorithms arrive in WebCrypto
The beta notes add several post-quantum algorithms to the Web Cryptography API: ML-KEM in 768 and 1024 variants, ML-DSA in 44, 65 and 87 variants, plus ChaCha20-Poly1305 and X-Wing. Google points to a draft specification for the details.
This is an API for developers, not a padlock that changes color in your address bar. Your banking site will not become quantum safe because you updated Chrome. A developer has to choose to call these algorithms, which means the benefit arrives site by site.
Still, shipping the building blocks in the browser is what lets that work start. Without them, a web app has to bundle its own cryptography code or wait.
Digital credentials can now start from the website
The Digital Credentials API gains issuance support. The notes say it lets an issuing website, such as a university, government agency or bank, securely start the process of provisioning a digital credential into your mobile wallet app.
On Android, that runs through the Credential Manager system, and on desktop Google describes a cross device approach using the CTAP protocol, similar to how credential presentation already works.
Picture finishing a degree and being offered the diploma as a wallet credential from the university’s own page, instead of a PDF you email around. Whether institutions actually offer that is up to them, and the notes do not say which ones plan to.
Smaller fixes that developers will notice first
Chrome 155 also adds a media-playback-while-not-visible permission policy. It lets a page embedding an iframe block audible playback when that frame is hidden or has zero width or height, which targets the odd case of sound coming from a page where nothing visible is playing.
Developers on shaky connections get a fix too. Today a failed module load is cached, so retrying just fails instantly. The change lets code call import() again and try a fresh load.
Apps with the window-management permission can also maximize, minimize and restore their windows, and block resizing with setResizable().
What to do while the rollout reaches you
You do not need to do anything. Chrome updates itself, and you can check your version at chrome://settings/help. Early stable builds go to a small share of Windows and Mac users first, so the update may not appear on your machine yet.
If you want to see how Google handled the previous release, our look at how Chrome 154 now asks before opening public HTTP sites covers the setting that changed there. Not a dramatic release, but a groundwork one, and the payoff depends on what sites build on top of it.






