← Back to release summary

Warning on insecure downloads

Category
Security
Type
No developer-visible change
Status
In developer trial (Behind a flag) (Chrome 117)
Intent stage
Start prototyping

Summary

To ensure users are aware of the risks of downloads delivered over an insecure connection, Chrome will display a bypassable warning for some downloads delivered over an insecure connection. Which downloads are warned about will depend on whether the user has enabled HTTPS-First Mode and whether the file type has a substantial risk of parsing vulnerabilities that can lead to code execution.

Standards & signals

View on chromestatus.com