Someone held a valid HTTPS certificate for google.com.gh without owning it
The padlock in your address bar is a narrow promise. It says the site you are on proved, at some point, that it controls that address. In late September somebody proved it for google.com.gh while owning nothing at all.
Google published the details on 6 October. The third-party operators that run three country domain registries were compromised in turn: Ghana's .gh on 22 September, Sierra Leone's .sl on the 25th, American Samoa's .as on the 27th. With control of the authoritative DNS records, the attackers could answer the one question a certificate authority asks before handing out a basic certificate. Twelve were issued across seven addresses, among them google.com.gh, youtube.com.gh, google.sl and youtube.as. Let's Encrypt issued eleven of them and ZeroSSL the twelfth. "Yes, certificates for Google and YouTube were issued, and have been revoked," wrote Matthew McPherrin of Let's Encrypt.
They were caught because every certificate issued is written into a public log, and Google watches those logs. Chrome then pushed out a CRLSet, which is the emergency list browsers carry of certificates to refuse. Google says its own systems were never touched and that other well-known brands were targeted the same way, without naming them.
So the lesson is not that HTTPS is broken. It is that the fix for something like this arrives inside a browser update, silently, and does nothing at all for a browser three versions behind. Tendvane's app update check runs through winget and will bring Chrome, Edge and Firefox up to current in one go, which is how blocks like that one actually reach your machine.