<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://chrome.security/feed.xml" rel="self" type="application/atom+xml" /><link href="https://chrome.security/" rel="alternate" type="text/html" /><updated>2026-08-11T21:57:53+00:00</updated><id>https://chrome.security/feed.xml</id><title type="html">chrome.security</title><subtitle>Chrome Security&apos;s mission is to make it safe to click on links.
</subtitle><entry><title type="html">The multi-layered defenses that harden Chrome against abusive notifications</title><link href="https://chrome.security/2026/08/11/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications.html" rel="alternate" type="text/html" title="The multi-layered defenses that harden Chrome against abusive notifications" /><published>2026-08-11T00:00:00+00:00</published><updated>2026-08-11T00:00:00+00:00</updated><id>https://chrome.security/2026/08/11/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications</id><content type="html" xml:base="https://chrome.security/2026/08/11/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications.html"><![CDATA[]]></content><author><name>Hannah Buonomo, Jonathan Li, and Nidhi Davawala</name></author><summary type="html"><![CDATA[Push notifications are a longstanding part of the open web, allowing developers to engage with users in real-time. However, bad actors have increasingly abused this system, bombarding people with deceptive and unwanted notifications. To combat this, Chrome Security has been on a multi-year journey, in collaboration with Firebase Cloud Messaging (FCM) and Safe Browsing, to significantly reduce notification abuse and improve the security and quality of the web ecosystem for everyone. After achieving a significant reduction in unwanted notification volume, reducing notifications on Android by over 7 billion a day in 2026 alone, today we’re pulling back the curtain on the multi-layered toolkit that secured this critical feature for billions of users.]]></summary></entry><entry><title type="html">Stronger with every update: How we’re making Chrome and the web safer in the AI Era</title><link href="https://chrome.security/2026/07/30/chrome-stronger-with-every-update.html" rel="alternate" type="text/html" title="Stronger with every update: How we’re making Chrome and the web safer in the AI Era" /><published>2026-07-30T00:00:00+00:00</published><updated>2026-07-30T00:00:00+00:00</updated><id>https://chrome.security/2026/07/30/chrome-stronger-with-every-update</id><content type="html" xml:base="https://chrome.security/2026/07/30/chrome-stronger-with-every-update.html"><![CDATA[]]></content><author><name>Chrome Security Team</name></author><summary type="html"><![CDATA[We’re living through a massive shift in the software security industry. Large Language Models (LLMs) are unlocking unprecedented capabilities for automated vulnerability discovery, scaling far beyond the limits of human security expertise, and requiring new approaches for staying ahead of attackers. This means deploying AI models at scale to find and fix hundreds of security bugs, faster than ever, with the goal of achieving greater resilience and comprehensive remediation. Here’s how we’re doing it.]]></summary></entry><entry><title type="html">Agent security considerations for WebMCP</title><link href="https://chrome.security/2026/06/09/agent-security-considerations-for-webmcp.html" rel="alternate" type="text/html" title="Agent security considerations for WebMCP" /><published>2026-06-09T00:00:00+00:00</published><updated>2026-06-09T00:00:00+00:00</updated><id>https://chrome.security/2026/06/09/agent-security-considerations-for-webmcp</id><content type="html" xml:base="https://chrome.security/2026/06/09/agent-security-considerations-for-webmcp.html"><![CDATA[<p>With <a href="https://github.com/webmachinelearning/webmcp">WebMCP</a>, web developers can build and expose structured tools to AI agents instrumenting the browser, including agents powered by extensions. Agents in the browser can operate within a user’s authenticated session, so it’s critical that agent developers design protections against malicious input from untrusted content. While this threat exists without WebMCP, we’ve identified some of the security techniques that are especially relevant for agents that use WebMCP.</p>]]></content><author><name>Julia Pagnucco and Alexandra Klepper</name></author><summary type="html"><![CDATA[With WebMCP, web developers can build and expose structured tools to AI agents instrumenting the browser, including agents powered by extensions. Agents in the browser can operate within a user’s authenticated session, so it’s critical that agent developers design protections against malicious input from untrusted content. While this threat exists without WebMCP, we’ve identified some of the security techniques that are especially relevant for agents that use WebMCP.]]></summary></entry><entry><title type="html">Evolving the Android &amp;amp; Chrome VRPs for the AI Era</title><link href="https://chrome.security/2026/04/30/evolving-the-android-chrome-vrps-for-the-ai-era.html" rel="alternate" type="text/html" title="Evolving the Android &amp;amp; Chrome VRPs for the AI Era" /><published>2026-04-30T00:00:00+00:00</published><updated>2026-04-30T00:00:00+00:00</updated><id>https://chrome.security/2026/04/30/evolving-the-android-chrome-vrps-for-the-ai-era</id><content type="html" xml:base="https://chrome.security/2026/04/30/evolving-the-android-chrome-vrps-for-the-ai-era.html"><![CDATA[]]></content><author><name>Alex Gough, Shailesh Saini, and Tony Mendez</name></author><summary type="html"><![CDATA[As the security research landscape evolves with AI, we're making changes in our programs to ensure we're rewarding the most challenging and impactful vulnerabilities in our products. This focus provides the most value to our security teams and helps keep users safe today, all while making sure security researchers continue to be rewarded for their efforts.]]></summary></entry><entry><title type="html">Protecting Cookies with Device Bound Session Credentials</title><link href="https://chrome.security/2026/04/09/protecting-cookies-with-device-bound.html" rel="alternate" type="text/html" title="Protecting Cookies with Device Bound Session Credentials" /><published>2026-04-09T00:00:00+00:00</published><updated>2026-04-09T00:00:00+00:00</updated><id>https://chrome.security/2026/04/09/protecting-cookies-with-device-bound</id><content type="html" xml:base="https://chrome.security/2026/04/09/protecting-cookies-with-device-bound.html"><![CDATA[]]></content><author><name>Benjamin Ackerman and Daniel Rubery, Chrome, and Guillaume Ehinger, Google Account Security</name></author><summary type="html"><![CDATA[Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.]]></summary></entry><entry><title type="html">Cultivating a robust and efficient quantum-safe HTTPS</title><link href="https://chrome.security/2026/02/27/cultivating-robust-and-efficient.html" rel="alternate" type="text/html" title="Cultivating a robust and efficient quantum-safe HTTPS" /><published>2026-02-27T00:00:00+00:00</published><updated>2026-02-27T00:00:00+00:00</updated><id>https://chrome.security/2026/02/27/cultivating-robust-and-efficient</id><content type="html" xml:base="https://chrome.security/2026/02/27/cultivating-robust-and-efficient.html"><![CDATA[<p>Today we’re announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a working group, PKI, Logs, And Tree Signatures (“PLANTS”), aiming to address the performance and bandwidth challenges that the increased size of quantum-resistant cryptography introduces into TLS connections requiring Certificate Transparency (CT). We recently shared our call to action to secure quantum computing and have written about challenges introduced by quantum-resistant cryptography and some of the steps we’ve taken to address them in earlier blog posts.</p>]]></content><author><name>Chrome Secure Web and Networking Team</name></author><summary type="html"><![CDATA[Today we’re announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a working group, PKI, Logs, And Tree Signatures (“PLANTS”), aiming to address the performance and bandwidth challenges that the increased size of quantum-resistant cryptography introduces into TLS connections requiring Certificate Transparency (CT). We recently shared our call to action to secure quantum computing and have written about challenges introduced by quantum-resistant cryptography and some of the steps we’ve taken to address them in earlier blog posts.]]></summary></entry><entry><title type="html">Fixing two ITW bugs in Chrome (Kawaiicon 2025)</title><link href="https://chrome.security/2025/12/23/kawaiicon-2025-fixing-windows-chrome-itw.html" rel="alternate" type="text/html" title="Fixing two ITW bugs in Chrome (Kawaiicon 2025)" /><published>2025-12-23T00:00:00+00:00</published><updated>2025-12-23T00:00:00+00:00</updated><id>https://chrome.security/2025/12/23/kawaiicon-2025-fixing-windows-chrome-itw</id><content type="html" xml:base="https://chrome.security/2025/12/23/kawaiicon-2025-fixing-windows-chrome-itw.html"><![CDATA[<iframe width="560" height="315" src="https://www.youtube-nocookie.com/embed/mxN8puPTLCs?si=zqTL0cb2Q4Wh6y_k" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen=""></iframe>]]></content><author><name>Alex Gough</name></author><summary type="html"><![CDATA[Alex Gough talks about fixing two sandbox escapes in Chrome and how to use postmortems to learn and make improvements to Chrome's IPC stack.]]></summary></entry><entry><title type="html">HTTPS certificate industry phasing out less secure domain validation methods</title><link href="https://chrome.security/2025/12/10/https-certificate-industry-phasing-out.html" rel="alternate" type="text/html" title="HTTPS certificate industry phasing out less secure domain validation methods" /><published>2025-12-10T00:00:00+00:00</published><updated>2025-12-10T00:00:00+00:00</updated><id>https://chrome.security/2025/12/10/https-certificate-industry-phasing-out</id><content type="html" xml:base="https://chrome.security/2025/12/10/https-certificate-industry-phasing-out.html"><![CDATA[<p>Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers.</p>]]></content><author><name>Chrome Root Program</name></author><summary type="html"><![CDATA[Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers.]]></summary></entry><entry><title type="html">Architecting Security for Agentic Capabilities in Chrome</title><link href="https://chrome.security/2025/12/08/architecting-security-for-agentic.html" rel="alternate" type="text/html" title="Architecting Security for Agentic Capabilities in Chrome" /><published>2025-12-08T00:00:00+00:00</published><updated>2025-12-08T00:00:00+00:00</updated><id>https://chrome.security/2025/12/08/architecting-security-for-agentic</id><content type="html" xml:base="https://chrome.security/2025/12/08/architecting-security-for-agentic.html"><![CDATA[<p>Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome to keep them safe by default, and this is a responsibility we take seriously. Following the recent launch of Gemini in Chrome and the preview of agentic capabilities, we want to share our approach and some new innovations to improve the safety of agentic browsing.</p>]]></content><author><name>Nathan Parker</name></author><summary type="html"><![CDATA[Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome to keep them safe by default, and this is a responsibility we take seriously. Following the recent launch of Gemini in Chrome and the preview of agentic capabilities, we want to share our approach and some new innovations to improve the safety of agentic browsing.]]></summary></entry><entry><title type="html">HTTPS by default</title><link href="https://chrome.security/2025/10/28/https-by-default.html" rel="alternate" type="text/html" title="HTTPS by default" /><published>2025-10-28T00:00:00+00:00</published><updated>2025-10-28T00:00:00+00:00</updated><id>https://chrome.security/2025/10/28/https-by-default</id><content type="html" xml:base="https://chrome.security/2025/10/28/https-by-default.html"><![CDATA[<p>One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user’s permission before the first access to any public site without HTTPS.</p>]]></content><author><name>Chris Thompson, Mustafa Emre Acer, Serena Chen, Joe DeBlasio, Emily Stark and David Adrian</name></author><summary type="html"><![CDATA[One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user’s permission before the first access to any public site without HTTPS.]]></summary></entry></feed>