Follow the latest coverage, related explainers and connected technology stories.
Attackers exploited control of the .gh, .sl, and .as domains to modify DNS records and pass automated validation processes, then obtain unauthorized TLS certificates for domains belonging to Google and other global brands. Chrome blocked the certificates identified by Google, but the company warned that browser-level intervention does not protect all users or guarantee the detection of every certificate.
Google is adding built-in support for the Encrypted Client Hello standard in Android 17 to hide domain names when HTTPS connections begin, alongside new restrictions on local network access, default activation of Certificate Transparency, and an option to disable 2G networks.