HTTPS by default
Google plans to make Chrome's “Always Use Secure Connections” setting the default with Chrome 154 in October 2026. Chrome will ask permission before users first access a public site without HTTPS.
Publisher
Stories with reporting from Google Security Blog, ranked by what is gaining ground now. Each story links to the original articles.
Google plans to make Chrome's “Always Use Secure Connections” setting the default with Chrome 154 in October 2026. Chrome will ask permission before users first access a public site without HTTPS.
Google announces a Chrome program to make HTTPS certificates secure against quantum computers. The effort addresses performance and bandwidth challenges associated with larger quantum-resistant cryptography, alongside work by the IETF PLANTS working group.
The Chrome Root Program and the CA/Browser Forum adopt new security requirements for HTTPS certificate issuers, phasing out less secure domain validation methods. The changes affect how certificate issuers validate domains and issue certificates.
Google is bringing Rust into the Pixel baseband as part of work to harden cellular modem firmware against exploitation. Pixel 9 already ships with mitigations for memory-safety vulnerabilities, and Google says it is advancing the effort for Pixel 10.
Google’s Open Source Security Team announces OSS Rebuild, a project that reproduces upstream artifacts to strengthen trust in open-source package ecosystems. It aims to help security teams detect compromised dependencies without adding work for upstream maintainers.
Google reports that memory-safety vulnerabilities fall below 20% of Android’s total vulnerabilities in 2025, as it applies its Rust-based memory-safety strategy. The company says the approach is not only preventing vulnerabilities in new code but also helping development move faster.
Google begins public availability of Device Bound Session Credentials for Windows users on Chrome 146, with macOS support planned for an upcoming Chrome release. DBSC is designed to protect session cookies by binding credentials to a device.
Google’s protected KVM (pKVM), the hypervisor behind the Android Virtualization Framework, achieves SESIP Level 5 security certification. The announcement describes it as the first software to receive this certification.
Google outlines plans for implementing post-quantum cryptography in Android as it prepares for security risks associated with quantum computing. The post is from Android and Google Play product managers and frames the work as part of protecting digital security as quantum capabilities advance.
Google's Android Red Team and Arm conduct a security analysis of Mali GPU software and firmware, components used in Android devices. The collaboration focuses on identifying and fixing vulnerabilities in the GPU stack.
Google describes its ongoing measures to mitigate indirect prompt injection in Workspace with Gemini. The attack vector uses malicious instructions embedded in data or tools to influence how a language model responds to a user’s request.
Google says Chrome is adapting its security approach for AI features, including Gemini in Chrome and agentic capabilities. The company frames this work as extending Chrome’s existing effort to protect users as these capabilities arrive.
Google describes support for Rowhammer research, a DRAM hardware vulnerability in which repeated access to one memory row can flip bits in adjacent rows. Such corruption can be exploited to access data, escalate privileges, or disrupt service, and hardware vendors have deployed mitigations.
Google says the Pixel 10 lineup supports C2PA Content Credentials in Pixel Camera and Google Photos, marking the first Pixel phones to include the feature. The technology is intended to improve transparency around digital media.
Google’s Android Security Team announces updates to Android Theft Protection, which is designed to help defend users before, during, and after a phone theft attempt. The team frames device theft as a risk of financial fraud and exposure of personal data.
Google's Chrome Security Team describes protections in Chrome on Android for users who enable Advanced Protection. The setting extends Google's Advanced Protection Program to device-level security for users needing heightened safeguards.
Google says Android's AI-assisted, layered scam defenses protect users from more than 10 billion suspected malicious calls and messages each month. The company says it is continuing to strengthen those protections.
Google’s Threat Intelligence teams identify indirect prompt injection as a priority threat area and monitor real-world adversarial activity involving attacks on web-based AI systems. The update concerns the evolving security risks of prompt injections that can target and compromise AI systems.
Google’s GenAI Security Team describes indirect prompt injection as an emerging attack vector, distinguishing it from direct attacks that place malicious commands into a prompt. The post presents a layered defense strategy for mitigating these attacks on generative AI systems.
Google describes its efforts to protect the Google Play and Android app ecosystems from malware, financial fraud, hidden subscriptions, and privacy violations. The company says bad actors are leveraging AI, and frames ecosystem trust as a security priority.