Google Inc. The plan to add new protection mechanisms against unsafe file downloads in Chrome. In Chrome 86, which is scheduled for release on October 26, downloading all types of files from links on pages opened via HTTPS will only be possible when the files are served using the HTTPS protocol. It is noted that downloading unencrypted files can be used for malicious activity through content replacement during MITM attacks (for example, malware targeting home routers can replace downloaded applications or intercept confidential documents).
The blocking will be implemented gradually, starting with the release of Chrome 82, in which warnings will be issued when attempting unsafe downloads of executable files from HTTPS pages. In Chrome 83, blocking for executable files will be enabled, and warnings will begin to be issued for archives. In Chrome 84, archiving blocking will be activated, and warnings will be issued for documents. In Chrome 85, documents will be blocked, and warnings will start to appear for unsafe downloads of images, videos, audio, and text, which will start to be blocked in Chrome 86.
In the more distant future, it is planned to completely cease support for downloading files without encryption. In releases for Android and iOS, the blocking will be implemented one release behind (for Chrome 82 — in 83, etc.). In Chrome 81, an option will appear in settings called 'chrome://flags/#treat-unsafe-downloads-as-active-content', which will enable warning outputs without waiting for the release of Chrome 82.
Source: opennet.ru
