Google has announced that it will no longer trust root CA certificates signed by Chunghwa Telecom and Netlock in the Chrome Root Store, due to repeated compliance failures and failure to make required improvements.
See also: Chrome vulnerabilities allow malicious code execution

This change will take effect with version 139 , which is scheduled to be released on August 1, 2025.
The tech giant says the decision is based on ongoing compliance failures, broken commitments to improve, and a lack of measurable progress. Chunghwa Telecom is the largest telecommunications provider in Taiwan, offering internet, mobile, and landline services. It operates a public Certificate Authority (CA) called ePKI and HiPKI , issuing digital certificates for secure online communication
Netlock is a major provider of digital certification in Hungary (electronic signatures, timestamps and TLS/SSL certificates), known primarily for its Arany (Gold Class) Root CA, which is widely used in Hungary and other European countries.
The Chrome Root Store is a list of trusted Authorities (CAs) maintained by Google that Chrome uses to verify HTTPS connections. Both Chunghwa Telecom and Netlock have been operating as public CAs for years, with their certificates included in the Chrome Root Store — meaning Chrome trusted them by default.
See also: Chrome: Over 100 malicious extensions detected
Starting August 1, 2025, Google Chrome will display the warning "Your connection is not private" when users visit websites that continue to use certificates issued by Chunghwa Telecom or Netlock, as their root CAs will no longer be trusted. While it will be technically possible to bypass the warning, this will disrupt the smooth browsing experience and create trust issues for visitors.

For this reason, it is recommended that administrators of affected websites act immediately and switch to a trusted Certification Authority as soon as possible.
Although Netlock and Chunghwa Telecom certificates issued up to July 31, 2025 will continue to be trusted by Chrome, it is recommended not to delay their inevitable replacement.
Google notes that affected organizations can bypass the trust change by adding the specific root certificates as locally trusted in their own environment. It is worth noting that this change does not affect the Microsoft Edge, Mozilla Firefox or Apple Safari, as they use different certificate trust systems.
See also: New Chrome vulnerability allows data leakage
A related and important point that arises from the above is the importance of trust management in digital certificates. Browsers like Google Chrome rely on root stores — lists of trusted Certificate Authorities — to determine which certificates can be considered valid and secure. When an organization, like Chunghwa Telecom or Netlock, repeatedly fails to comply with security and transparency standards, it is removed from that root store.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
