Chrome 154 makes its “Always Use Secure Connections” setting the default for public websites: when Chrome cannot connect to a public site over HTTPS, it asks before continuing over HTTP. A saved bookmark that explicitly starts with http:// may encounter the prompt, but Google has not said bookmarks will be affected more often than other kinds of links. Regularly visited insecure sites are not expected to trigger repeated warnings.
What changes in Chrome 154
Google’s Chrome 154 release notes list “Ask before HTTP on by default.” The stable release date given in those notes is September 22, 2026. The change is documented for Android, ChromeOS, Linux, macOS, and Windows unless otherwise noted.
Chrome tries to use HTTPS where possible. If a public site cannot be reached securely and the navigation would use HTTP, Chrome asks for permission before proceeding. HTTP does not encrypt the connection, so information exchanged with the site may be exposed or altered in transit. The prompt is a security decision point, not proof that the site itself is malicious.
Google announced the planned default change on October 28, 2025. Its later Chrome 154 release notes list the behavior as shipped. The announcement describes expected behavior, not a guarantee that every person will see the same prompt frequency.
#1 Best Overall
Why an old bookmark may bring up the prompt
Check the address saved in the bookmark. If it begins with http://, opening it can start an insecure navigation. If the destination supports HTTPS, use its secure address instead; you can often change the bookmark to begin with https:// after confirming that the secure page loads correctly.
This is a practical implication of the setting, not a finding that bookmarks are uniquely or first affected. The same kind of HTTP navigation can come from a typed address, a search result, or a link. Google says Chrome focuses prompts on new or not recently visited insecure sites and does not repeatedly warn while a user regularly visits one. An old bookmark may therefore prompt if its destination is new or has not been visited recently, but it is not certain to do so on every opening.
Rank #2
What to do when Chrome asks
- If the site offers HTTPS: cancel the insecure navigation and open the site’s secure address. Update the bookmark or shortcut once you have verified the HTTPS destination.
- If the site does not offer HTTPS: continue only when you understand why you need the site and trust both the destination and the network you are using. Avoid entering passwords, payment details, or other sensitive information over an unencrypted connection.
- If you do not recognize the destination or have no reason to use it: go back rather than dismissing the prompt reflexively. Contact the site owner if you need access.
Google’s stated concern is that an attacker may interfere with a link that does not use HTTPS, redirecting a user to attacker-controlled resources and exposing them to malware, targeted exploitation, or social engineering. The warning indicates an insecure connection; it does not by itself establish that an attack is happening.
Public websites are not the same as local devices or intranets
The default change is the public-sites variant of “Always Use Secure Connections.” Local network addresses and single-label hostnames—such as names used for company systems—may not have publicly trusted certificates. Google documents a broader mode that warns on any insecure site, including private destinations.
Rank #3
| Mode | Destinations covered | Practical trade-off |
|---|---|---|
| Public-sites-only warning | Public websites reached insecurely over HTTP | Protects public-site navigations while reducing prompts for people using local devices or private network services. |
| All insecure sites | Public and private/local destinations reached insecurely | Extends warnings to more destinations, but may interrupt intranet or device-configuration workflows that lack publicly trusted certificates. |
Google’s guidance describes these modes and controls for managed deployments in its Android security article. No URL was provided for that article here, so a direct link is not included.
Advice for website owners
Use Chrome’s setting before making changes mandatory for users to identify HTTP destinations your organization still depends on. Move public pages and redirects to HTTPS, then check links, saved URLs, and shortcuts that may still point to HTTP. An HTTP-to-HTTPS redirect still begins with an insecure request; the browser prompt makes that initial navigation visible instead of treating the redirect as an invisible detail.
Google says many remaining HTTP navigations are to sites that immediately redirect to HTTPS. That does not remove the need to secure the first request: migrating links and redirects helps avoid the insecure initial connection as well as the prompt.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Advice for Chrome administrators
Chrome 154’s release notes identify the HttpsOnlyMode enterprise policy. Google’s managed Chrome documentation also identifies HTTPAllowlist for exceptions. Administrators should review the desired public-sites-only or all-sites behavior, test internal services and local device pages, and determine whether specific exceptions are necessary before applying a fleet-wide configuration.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
How often might users see prompts?
Google reported results from its Chrome 141 experiment, not a guarantee for Chrome 154 or for an individual user: the median user saw fewer than one warning per week, and the 95th-percentile user saw fewer than three per week. Google also said warnings accounted for considerably less than 3% of navigations in that experiment. These are Google’s own estimates, not independent measurements.
Separately, Google said more than 1 billion users who had opted into Enhanced Safe Browsing were to receive the public-sites variant in Chrome 147 before the broader Chrome 154 default rollout. That figure describes Google’s announced rollout population, not the number of users who will encounter a prompt.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

