Chrome is finally turning a four-year-old opt-in feature into a hard default.
Google announced that Chrome 154, due in October 2026, will enable "Always Use Secure Connections" for every user. The feature has existed since 2022 but required manual activation; from next year, Chrome will show a bypassable warning before loading any public site that still runs plain HTTP. Private sites, including local IP addresses and intranet shortlinks, are mostly exempt, because issuing a trusted HTTPS certificate for a non-public hostname remains genuinely complicated. As a staged rollout, Chrome 147 in April 2026 will flip the switch first for the roughly 1 billion users already enrolled in Enhanced Safe Browsing.
The case for acting now comes down to a plateau. HTTPS adoption climbed from around 30% of Chrome navigations in 2015 to the 95-99% range by 2020, and then largely stopped moving. Attackers only need a single unencrypted navigation to hijack where a browser ends up, so the remaining gap is a real threat surface, not a rounding error. Experiment data found the median user sees fewer than one warning per week, which makes the practical friction lower than it sounds.
The loudest objections will come from IT departments managing intranet portals and legacy device configuration pages that still ship over HTTP. Google's advice to those teams: enable the setting today, find which internal sites break, and fix them before October.