Chrome To Warn Users Before Accessing HTTP Sites Starting Next Year
Chrome will begin warning users before accessing HTTP sites starting next year, enhancing internet security and encouraging wide HTTPS adoption.
Google announced that from the launch of Chrome 154 in October 2026, it will be able to enable “Always Use Secure Connections” as a default. This will mean that Chrome will try to connect to websites with HTTPS which is the secure version of HTTP.
When users attempt to connect to websites that are not encrypted with HTTPS security, Chrome displays a warning that is bypassable that highlights the security risks associated with.
Gradual Rollout Begins in April 2026
The feature will be launched in stages. Chrome 147, releasing in April 2026 will enable the default setting for the more than one billion users who are enrolled in the Enhanced Safe Browsing.
Six months after, it will be an option for every Chrome users around the world.
What Does This Mean for Users?
The warning system is only applicable only to publicly accessible websites that are not private, including private IP addresses that are local to the user, hostnames with a single label and internal shortlinks.
According to Chris Thompson and the Chrome Security Team:
“HTTP navigations to private sites can still be risky, but are typically less dangerous than their public site counterparts because there are fewer ways for an attacker to take advantage of these HTTP navigations.”
Here’s an example of what the warning will look like:

This latest notification is designed to alert users of the security risks of connections that are not encrypted, like the injection of malware or targeted exploits.
Warning Frequency and Design
To ensure that users are not interrupted by overly-prompting messages, Chrome limits how often warnings appear on the same websites that are not secure.
Median users will see fewer than one warning every week and those in the 95th percentile will see less than three warnings each week.
A sample warning screen users can notice emphasizes the dangers and gives the option for a quick exit or returning to security.
HTTPS Adoption Status in Chrome
Google’s statistics show that HTTPS use is currently between 95-99% across all platforms. If you exclude private websites the figures are slightly better (about 5%).
Windows users can access 98% HTTPS when they visit websites that are public, Android and macOS users surpass 99%, and Linux users are 97%.
Despite these rates, the small portion of HTTP traffic is still millions of potentially vulnerable visits.
Why This Update Matters
Unsecured HTTP connections can pose serious security threats. Criminals can exploit the unencrypted connections to insert malware, phishing schemes or any other potentially harmful content.
Google’s transparency reports reveal that even though HTTPS adoption increased dramatically from 2015 until 2020, it has since slowed and some websites are still providing content that is not secure.
This new setting will force webmasters to switch to HTTP and HTTPS over the course of the next 12 months or their users will be prompted to warn visitors.
How to Prepare and Test
Website owners can proactively enable “Always Use Secure Connections” today by navigating to chrome://settings/security and turning on the option.
This will allow them to see the effects of any warnings that might impact their website’s traffic and make sure that the process is smoother.
Looking Ahead
Google continues to collaborate with those responsible for the largest volumes of HTTP traffic to promote migration. A lot of websites currently offering HTTP use the technology to direct users towards HTTPS locations, but this has a security hole which Google hopes to fill with the brand-new warning mechanism.
This update is a major move in the long-term goal of Chrome to make secure, secure browsing the standard for all internet users and ensure the safety of users across the internet.
Bottom Line
This update is vital for both website users and administrators as it emphasizes how important secure connection are for protecting online experiences. Website owners must prioritize the migration to HTTPS quickly to avoid interruptions and ensure trust among users.