Compare / versions
Chrome 154 vs Chrome 153
What changed between the two Chrome majors on the fleet — new features, removals, the new HTTP warning and why automated sessions don't see it — and which of it a site can use to tell a browser's version, or to tell that the version is a lie.
Chrome 153 went stable on 8 September 2026 and 154 on 22 September. The fleet runs 154 as stable and keeps 153 as a pinned previous major ({"version": "153"}) until it rotates out; 155 and 157 are available as beta and dev. Below: what Google shipped and removed in each, what we could measure as different from inside a page and on the wire, which of those differences matter for detection, and what can be configured — by you in the launch, by us on the fleet, or by nobody.
What 154 adds
From the Chrome 154 release notes. Items marked measured show up in the probe table below.
- JavaScript:
Iterator.prototype.includes(measured: present in 154, absent in 153); the JavaScript Self-Profiling API in dedicated workers. - CSS and layout:
scroll-marker-groupgetslinksandtabsmodes;text-decoration-insetfor the start and end of underlines;FontFace.widthand thefont-widthdescriptor as aliases forstretch(measured);CSSStyleValueavailable in workers; responsively-sized<iframe>; popovers and dialogs light-dismiss onclickinstead of pointer events, so scrolling no longer closes them. - Network: the
WebSocketconstructor takes an options dictionary ({ protocols }, an extension point for later options) and atargetAddressSpacefor local destinations; a fetch's abort reason is forwarded toResponsemethods and streams; Background Fetch now enforces CORS and needs the Local Network Access permission for local servers. - Security and privacy: Ask before HTTP is on by default — Chrome warns before loading a plain
http://page; administrators control it with theHttpsOnlyModepolicy. Measured: the warning did not appear in a fleet session — a plain-HTTP JSON endpoint loaded directly in both versions, because Playwright launches Chromium with theHttpsUpgradesfeature disabled (see below). Secure Payment Confirmation validates the dialog locale. Origin trial: Private Verification Tokens, which carry a site's trust in a user into Incognito to reduce CAPTCHA friction. - Service workers and devices: an opt-in
ServiceWorkerAutoPreloadmode that sends the network request in parallel with service-worker startup; WebHID listed for this release.
What 153 added, and what it took away
- Added in 153: single-axis scroll containers (
overflowwithclipon one axis),scroll-axis-lock, declarative<camera>and<microphone>capability elements (measured: present in both),Iterator.prototype.joinandIterator.zip(measured: both), IAMF spatial-audio decoding,renderSizeHintforAudioContext, the WebGPUbuffer_viewWGSL feature, XML parsing moved to a memory-safe Rust parser, JS Self-Profiling markers (origin trial). - Deprecated or removed from 153 on: the Privacy Sandbox advertising APIs — Protected Audience, Shared Storage, Attribution Reporting, Related Website Sets and
document.requestStorageAccessFor— and the non-standard_currentnavigation target. Measured:document.requestStorageAccessForis still a function in 153 and gone in 154;navigator.joinAdInterestGroupanddocument.browsingTopicswere still present in both at measurement time;window.sharedStorageandwindow.attributionReportingwere absent in both.
What is identical
Everything on the wire. JA4, the peetprint, the Akamai HTTP/2 fingerprint, cipher and extension counts and the header order are byte-for-byte the same in 153 and 154 (the JA3 hash differs between any two Chrome runs because of GREASE randomisation — never use it to compare builds). Canvas output, WebGL strings, screen, window metrics, plugins, permissions and navigator.webdriver (false on the fleet) are also identical. Only the host's core count differs, and that is the fleet node, not the version.
What affects detection
- The version is declared in four places and they must agree: the reduced user agent (
Chrome/154.0.0.0), thesec-ch-uabrands header,navigator.userAgentData.brandsand the high-entropyfullVersionList. 154 also changes the GREASE brand token and its position (Not A(Brand;99first in 154,Not_A Brand;8second in 153). Spoofing the UA string alone leaves the client hints andfullVersionListon the old version — a one-line inconsistency check. Run the real version instead: both are a launch option here. - Feature presence is a version fingerprint:
Iterator.prototype.includes,FontFace.widthand the disappearance ofdocument.requestStorageAccessForseparate 154 from 153 without reading any header. A "Chrome 154" user agent on a 153 engine (or an older Chromium build) fails this silently. - Plain-HTTP targets keep working. A hand-launched Chrome 154 stops at a warning page before loading
http://sites; an automated one on the fleet does not (measured:http://ip-api.com/jsonloaded directly in 154 and 153), because Playwright starts Chromium with--disable-features=…HttpsUpgrades…. A site can't see the difference from inside a page; a one-offhttp://navigation that *isn't* warned about is only visible to someone watching the browser. - Private Verification Tokens (origin trial) is Google's own answer to "trusted user, fresh profile" — relevant to anyone whose problem is CAPTCHA friction on clean sessions, not available to automation.
- Nothing changed at the TLS or HTTP/2 layer, so anti-bot systems that keyed on Chrome 153's JA4 keep matching 154; only JS-level version checks move.
Configurable — by you, by us, by nobody
| Item | Who controls it | How |
|---|---|---|
| Which major runs | You | version: "153" while it is pinned on the fleet; channel: "beta" / "dev" for 155 and 157; omit both for stable. See Chrome. |
Ask before HTTP (the http:// warning page) | Playwright / cdpfleet | Already off for fleet sessions: Playwright's launcher disables Chromium's HttpsUpgrades feature (measured: no warning in 154). The HttpsOnlyMode enterprise policy is the supported switch if Chrome ever stops honouring the flag; only the fleet can set it. Nothing for you to do; http:// targets load as in 153. |
| Local Network Access permission (Background Fetch to local servers) | Not relevant on the fleet | The browser runs on our servers; "local" is our network, which sessions cannot reach. |
ServiceWorkerAutoPreload | The site | Opt-in by the site's service worker; nothing to set on the browser. |
WebSocket options and targetAddressSpace | Page scripts | New API surface, available to any script you run in the page. |
Privacy Sandbox APIs (requestStorageAccessFor, Protected Audience, Shared Storage, Attribution Reporting) | Nobody | Removed or being removed from Chromium; no flag or policy brings document.requestStorageAccessFor back in 154. Sites that relied on it fall back to the Storage Access API prompt. |
_current navigation target | Nobody | Removed in 153. |
| Fingerprint surface (UA, client hints, canvas, WebGL, screen) | You, per context | Unchanged between the versions; set with newContext options as before, or use Camoufox when the identity itself must change. |
Measured on the fleet (2026-10-04)
One headful launch of each on the production fleet through the same proxy, probed from inside a page and via tls.peet.ws. Timings are a single sample; core counts are the node's.
Launch and cost
Single run; timings depend on the proxy and on fleet load.
| Chrome 154 | Chrome 153 | |
|---|---|---|
| Launch body | {"headless":false} | {"headless":false,"version":"153"} |
| Threads used | 2 (linux_headful) | 2 (linux_headful) |
| Browser version | 154.0.8037.97 | 153.0.8010.36 |
| Launch request → browser ready | 0.7 s | 1.3 s |
| Playwright connect | 0.0 s | 0.1 s |
| Load example.com | 0.5 s | 1.2 s |
| Load tls.peet.ws/api/all | 0.6 s | 3.2 s |
What the network sees
From tls.peet.ws/api/all, requested by the browser itself. JA3 hashes change between runs of the same build (GREASE), so compare JA4 and the HTTP/2 fingerprint.
| Chrome 154 | Chrome 153 | |
|---|---|---|
| HTTP version | h2 | h2 |
| JA4 | t13d1517h2_8daaf6152771_cb7bf5808d99 | t13d1517h2_8daaf6152771_cb7bf5808d99 |
| Peetprint hash | fc97c1cdfb1409c9a9326c1b726d1dee | fc97c1cdfb1409c9a9326c1b726d1dee |
| Akamai HTTP/2 fingerprint | 1:65536;2:0;4:6291456;6:262144|15663105|0|m,a,s,p | 1:65536;2:0;4:6291456;6:262144|15663105|0|m,a,s,p |
| Cipher suites / extensions | 16 / 19 | 16 / 19 |
| Header order (first 12) | method, authority, scheme, path, sec-ch-ua, sec-ch-ua-mobile, sec-ch-ua-platform, upgrade-insecure-requests, user-agent, accept, sec-fetch-site, sec-fetch-mode | method, authority, scheme, path, sec-ch-ua, sec-ch-ua-mobile, sec-ch-ua-platform, upgrade-insecure-requests, user-agent, accept, sec-fetch-site, sec-fetch-mode |
What page scripts see
Read with page.evaluate on example.com. Cores and memory are the server's and vary between fleet nodes.
| Chrome 154 | Chrome 153 | |
|---|---|---|
| navigator.userAgent | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/154.0.0.0 Safari/537.36 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 |
| UA-CH brands | Chromium 154 · Google Chrome 154 · Not A(Brand 99 | Google Chrome 153 · Not_A Brand 8 · Chromium 153 |
| UA-CH full version list | Chromium 154.0.8037.97 · Google Chrome 154.0.8037.97 · Not A(Brand 99.0.0.0 | Google Chrome 153.0.8010.36 · Not_A Brand 8.0.0.0 · Chromium 153.0.8010.36 |
| navigator.platform / vendor | Linux x86_64 / Google Inc. | Linux x86_64 / Google Inc. |
| Languages | en-US, en | en-US, en |
| Timezone / locale | UTC / en-US | UTC / en-US |
| Screen (w×h×availW×availH×depth) | 1280x720x1280x720x24 | 1280x720x1280x720x24 |
| Window outer / inner / DPR | 1288x805 / 1280x720 / 1 | 1288x805 / 1280x720 / 1 |
| hardwareConcurrency / deviceMemory | 64 / 32 | 64 / 32 |
| WebGL vendor | Google Inc. (Google) | Google Inc. (Google) |
| WebGL renderer | ANGLE (Google, Vulkan 1.3.0 (SwiftShader Device (Subzero) (0x0000C0DE)), SwiftShader driver) | ANGLE (Google, Vulkan 1.3.0 (SwiftShader Device (Subzero) (0x0000C0DE)), SwiftShader driver) |
| WebGL version | WebGL 2.0 (OpenGL ES 3.0 Chromium) | WebGL 2.0 (OpenGL ES 3.0 Chromium) |
| WebGPU (navigator.gpu) | yes | yes |
| Canvas hash | f5a94624 | f5a94624 |
| navigator.webdriver | no | no |
| window.chrome / navigator.connection | yes / yes | yes / yes |
| Plugins / PDF viewer | 5 / yes | 5 / yes |
| Notification.permission / permissions.query | default / prompt | default / prompt |
Web platform features
Presence probes; a user agent that claims one version while exposing another's features is a detectable inconsistency.
| Chrome 154 | Chrome 153 | |
|---|---|---|
Iterator.prototype.includes (new in Chrome 154) | yes | no |
FontFace.width (new in Chrome 154) | yes | no |
CSS text-decoration-inset (new in Chrome 154) | no | no |
Iterator.prototype.join (Chrome 153) | yes | yes |
Iterator.zip (Chrome 153) | yes | yes |
CSS scroll-axis-lock (Chrome 153) | no | no |
<camera> element (Chrome 153) | yes | yes |
document.requestStorageAccessFor (deprecated in 153) | no | yes |
Topics API (document.browsingTopics) | yes | yes |
Protected Audience (navigator.joinAdInterestGroup) | yes | yes |
Shared Storage (window.sharedStorage) | no | no |
Attribution Reporting (window.attributionReporting) | no | no |
| Private Aggregation | no | no |
WebHID (navigator.hid) | yes | yes |
bot.sannysoft.com
The classic headless-detection test page; what it marks red.
| Chrome 154 | Chrome 153 | |
|---|---|---|
| Checks / failed | 57 / 1 | 57 / 1 |
| Failed checks | WebGL Renderer | WebGL Renderer |
A plain-HTTP URL (http://ip-api.com/json)
Chrome 154 warns before loading insecure HTTP by default — does that reach an automated session?
| Chrome 154 | Chrome 153 | |
|---|---|---|
| Final URL | http://ip-api.com/json/?fields=status | http://ip-api.com/json/?fields=status |
| HTTP status | 200 | 200 |
| Content loaded / warning page first | yes / no | yes / no |
Playwright over the remote connection
Which client features work on this side.
| Chrome 154 | Chrome 153 | |
|---|---|---|
| page.evaluate runs in the page's own world | yes | yes |
| addInitScript visible to page scripts | yes | yes |
| Console events | yes | yes |
| Request interception (page.route) | yes | yes |
| Screenshot | yes | yes |
| yes | yes | |
| Mobile device emulation | yes | yes |
| Tracing | yes | yes |
Rows where the two sides differ are highlighted. IP addresses are replaced with placeholders (203.0.113.x). The probe is compare/probe.mjs in our repository; the raw result is below.
Raw output
{
"ran_at": "2026-10-04T21:08:09.390Z",
"sides": [
{
"label": "Chrome 154",
"engine": "chrome",
"body": {
"headless": false
},
"launch": {
"browser": "chrome",
"resource_class": "linux_headful",
"weight": 2,
"launch_ms": 653,
"connect_ms": 32,
"example_ms": 512,
"peet_ms": 641
},
"network": {
"http_version": "h2",
"ja4": "t13d1517h2_8daaf6152771_cb7bf5808d99",
"ja3_hash": "b3289d099f33354de20fb487a2d42241",
"peetprint_hash": "fc97c1cdfb1409c9a9326c1b726d1dee",
"ciphers": 16,
"extensions": 19,
"akamai_h2": "1:65536;2:0;4:6291456;6:262144|15663105|0|m,a,s,p",
"akamai_h2_hash": "52d84b11737d980aef856699f885ca86",
"header_order": [
"method",
"authority",
"scheme",
"path",
"sec-ch-ua",
"sec-ch-ua-mobile",
"sec-ch-ua-platform",
"upgrade-insecure-requests",
"user-agent",
"accept",
"sec-fetch-site",
"sec-fetch-mode"
]
},
"page": {
"user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/154.0.0.0 Safari/537.36",
"platform": "Linux x86_64",
"vendor": "Google Inc.",
"languages": [
"en-US",
"en"
],
"hardware_concurrency": 64,
"device_memory": 32,
"max_touch_points": 0,
"webdriver": false,
"plugins": 5,
"pdf_viewer": true,
"ua_data": {
"brands": [
{
"brand": "Chromium",
"version": "154"
},
{
"brand": "Google Chrome",
"version": "154"
},
{
"brand": "Not A(Brand",
"version": "99"
}
],
"mobile": false,
"platform": "Linux",
"architecture": "x86",
"bitness": "64",
"formFactors": [
"Desktop"
],
"fullVersionList": [
{
"brand": "Chromium",
"version": "154.0.8037.97"
},
{
"brand": "Google Chrome",
"version": "154.0.8037.97"
},
{
"brand": "Not A(Brand",
"version": "99.0.0.0"
}
],
"model": "",
"platformVersion": "",
"uaFullVersion": "154.0.8037.97",
"wow64": false
},
"screen": "1280x720x1280x720x24",
"window": {
"outer": "1288x805",
"inner": "1280x720",
"dpr": 1
},
"timezone": "UTC",
"locale": "en-US",
"webgl": {
"vendor": "Google Inc. (Google)",
"renderer": "ANGLE (Google, Vulkan 1.3.0 (SwiftShader Device (Subzero) (0x0000C0DE)), SwiftShader driver)",
"version": "WebGL 2.0 (OpenGL ES 3.0 Chromium)"
},
"canvas_hash": "f5a94624",
"webgpu": true,
"chrome_object": true,
"chrome_runtime": false,
"notification_permission": "default",
"notification_query": "prompt",
"has_focus": true,
"connection_api": true,
"stack_read_by_debugger": false,
"features": {
"iterator_includes": true,
"iterator_join": true,
"iterator_zip": true,
"fontface_width": true,
"css_text_decoration_inset": false,
"css_scroll_axis_lock": false,
"websocket_options_bag": null,
"camera_element": true,
"topics_api": true,
"protected_audience": true,
"shared_storage": false,
"attribution_reporting": false,
"request_storage_access_for": false,
"webhid": true,
"private_aggregation": false
}
},
"page_main_world": null,
"sannysoft": {
"checks": 57,
"failed": 1,
"failed_names": [
"WebGL Renderer"
],
"passed": 30
},
"plain_http": {
"final_url": "http://ip-api.com/json/?fields=status",
"status": 200,
"title": "",
"loaded": true,
"warning_page": false,
"page_text": "{\"status\":\"success\"}"
},
"playwright": {
"evaluate_in_main_world": true,
"console_events": true,
"init_script": true,
"route": true,
"screenshot": true,
"pdf": true,
"mobile_emulation": true,
"tracing": true
},
"browser_version": "154.0.8037.97"
},
{
"label": "Chrome 153",
"engine": "chrome",
"body": {
"headless": false,
"version": "153"
},
"launch": {
"browser": "chrome",
"resource_class": "linux_headful",
"weight": 2,
"launch_ms": 1302,
"connect_ms": 126,
"example_ms": 1201,
"peet_ms": 3235
},
"network": {
"http_version": "h2",
"ja4": "t13d1517h2_8daaf6152771_cb7bf5808d99",
"ja3_hash": "8c199af547de1666a4e3d7fade58dbb2",
"peetprint_hash": "fc97c1cdfb1409c9a9326c1b726d1dee",
"ciphers": 16,
"extensions": 19,
"akamai_h2": "1:65536;2:0;4:6291456;6:262144|15663105|0|m,a,s,p",
"akamai_h2_hash": "52d84b11737d980aef856699f885ca86",
"header_order": [
"method",
"authority",
"scheme",
"path",
"sec-ch-ua",
"sec-ch-ua-mobile",
"sec-ch-ua-platform",
"upgrade-insecure-requests",
"user-agent",
"accept",
"sec-fetch-site",
"sec-fetch-mode"
]
},
"page": {
"user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36",
"platform": "Linux x86_64",
"vendor": "Google Inc.",
"languages": [
"en-US",
"en"
],
"hardware_concurrency": 64,
"device_memory": 32,
"max_touch_points": 0,
"webdriver": false,
"plugins": 5,
"pdf_viewer": true,
"ua_data": {
"brands": [
{
"brand": "Google Chrome",
"version": "153"
},
{
"brand": "Not_A Brand",
"version": "8"
},
{
"brand": "Chromium",
"version": "153"
}
],
"mobile": false,
"platform": "Linux",
"architecture": "x86",
"bitness": "64",
"formFactors": [
"Desktop"
],
"fullVersionList": [
{
"brand": "Google Chrome",
"version": "153.0.8010.36"
},
{
"brand": "Not_A Brand",
"version": "8.0.0.0"
},
{
"brand": "Chromium",
"version": "153.0.8010.36"
}
],
"model": "",
"platformVersion": "",
"uaFullVersion": "153.0.8010.36",
"wow64": false
},
"screen": "1280x720x1280x720x24",
"window": {
"outer": "1288x805",
"inner": "1280x720",
"dpr": 1
},
"timezone": "UTC",
"locale": "en-US",
"webgl": {
"vendor": "Google Inc. (Google)",
"renderer": "ANGLE (Google, Vulkan 1.3.0 (SwiftShader Device (Subzero) (0x0000C0DE)), SwiftShader driver)",
"version": "WebGL 2.0 (OpenGL ES 3.0 Chromium)"
},
"canvas_hash": "f5a94624",
"webgpu": true,
"chrome_object": true,
"chrome_runtime": false,
"notification_permission": "default",
"notification_query": "prompt",
"has_focus": true,
"connection_api": true,
"stack_read_by_debugger": false,
"features": {
"iterator_includes": false,
"iterator_join": true,
"iterator_zip": true,
"fontface_width": false,
"css_text_decoration_inset": false,
"css_scroll_axis_lock": false,
"websocket_options_bag": null,
"camera_element": true,
"topics_api": true,
"protected_audience": true,
"shared_storage": false,
"attribution_reporting": false,
"request_storage_access_for": true,
"webhid": true,
"private_aggregation": false
}
},
"page_main_world": null,
"sannysoft": {
"checks": 57,
"failed": 1,
"failed_names": [
"WebGL Renderer"
],
"passed": 29
},
"plain_http": {
"final_url": "http://ip-api.com/json/?fields=status",
"status": 200,
"title": "",
"loaded": true,
"warning_page": false,
"page_text": "{\"status\":\"success\"}"
},
"playwright": {
"evaluate_in_main_world": true,
"console_events": true,
"init_script": true,
"route": true,
"screenshot": true,
"pdf": true,
"mobile_emulation": true,
"tracing": true
},
"browser_version": "153.0.8010.36"
}
]
}Bottom line
For automation the headline change of 154 — the warning before plain http:// pages — turns out not to reach fleet sessions: Playwright launches Chromium with HTTPS upgrades disabled, and we measured http:// targets loading as before. What does change is that a version is now checkable from inside the page in at least three new ways (Iterator.prototype.includes, FontFace.width, the missing requestStorageAccessFor); the cheapest way to pass those checks is to run the version you claim.
Everything that an anti-bot system reads on the wire is identical between the two, so moving from 153 to 154 (or back, while 153 is pinned) does not change your TLS or HTTP/2 standing — only your JavaScript-level version story.