1. Image: Google Security Blog

    HTTPS by default

    Google plans to make Chrome's “Always Use Secure Connections” setting the default with Chrome 154 in October 2026. Chrome will ask permission before users first access a public site without HTTPS.

  2. Cultivating a robust and efficient quantum-safe HTTPS

    Google announces a Chrome program to make HTTPS certificates secure against quantum computers. The effort addresses performance and bandwidth challenges associated with larger quantum-resistant cryptography, alongside work by the IETF PLANTS working group.

  3. Bringing Rust to the Pixel Baseband

    Google is bringing Rust into the Pixel baseband as part of work to harden cellular modem firmware against exploitation. Pixel 9 already ships with mitigations for memory-safety vulnerabilities, and Google says it is advancing the effort for Pixel 10.

  4. Image: Google Security Blog

    Introducing OSS Rebuild: Open Source, Rebuilt to Last

    Google’s Open Source Security Team announces OSS Rebuild, a project that reproduces upstream artifacts to strengthen trust in open-source package ecosystems. It aims to help security teams detect compromised dependencies without adding work for upstream maintainers.

  5. Image: Google Security Blog

    Rust in Android: move fast and fix things

    Google reports that memory-safety vulnerabilities fall below 20% of Android’s total vulnerabilities in 2025, as it applies its Rust-based memory-safety strategy. The company says the approach is not only preventing vulnerabilities in new code but also helping development move faster.

  6. Further Hardening Android GPUs

    Google's Android Red Team and Arm conduct a security analysis of Mali GPU software and firmware, components used in Android devices. The collaboration focuses on identifying and fixing vulnerabilities in the GPU stack.

  7. Image: Google Security Blog

    Supporting Rowhammer research to protect the DRAM ecosystem

    Google describes support for Rowhammer research, a DRAM hardware vulnerability in which repeated access to one memory row can flip bits in adjacent rows. Such corruption can be exploited to access data, escalate privileges, or disrupt service, and hardware vendors have deployed mitigations.

  8. Image: Google Security Blog

    Advancing Protection in Chrome on Android

    Google's Chrome Security Team describes protections in Chrome on Android for users who enable Advanced Protection. The setting extends Google's Advanced Protection Program to device-level security for users needing heightened safeguards.