Support our independent tech coverage. Chrome Unboxed is written by real people, for real people—not search algorithms. Join Chrome Unboxed Plus for just $2 a month to get an ad-free experience, access to our private Discord, and more. Learn more about membership here.
START FREE TRIAL (MONTHLY)START FREE TRIAL (ANNUAL)
Google has officially begun rolling out ChromeOS 151 (version 16733.48.0 / Browser version 151.0.7922.141) to Chromebooks and ChromeOS Flex devices on the Stable channel. While milestone 151 is a modest visual refresh on the surface, the official release notes show off a handful of under-the-hood stability improvements, crucial enterprise policy transitions, and a massive list of 18 security patches.
New Tab page auto-hiding bookmark bar
If you like to keep your workspace minimal and distraction-free, ChromeOS 151 introduces a welcome quality-of-life tweak for the browser’s top bar.
- Smart Auto-Hide: Under Settings > Appearance, you will now find explicit controls for bookmark bar visibility. If Chrome detects that you don’t interact with the bookmark bar regularly on the New Tab page, it can automatically tuck it away to maximize vertical screen real estate.
- One-Click Restore: Whenever the bar is hidden due to low usage, a subtle notification appears allowing you to restore it permanently with a single click.
- Admin Controls: Enterprise and education administrators can enforce persistent visibility across fleets using the updated BookmarkBarEnabled policy.
Enhanced Safe Browsing for Gemini in Chrome
As Google continues to weave Gemini deeper into the Chrome browser experience, keeping AI-assisted browsing safe against zero-day threats is a top priority.
- Real-Time Phishing Protection: In ChromeOS 151, Google has integrated real-time Safe Browsing protections directly into active Gemini sessions in Chrome.
- Zero-Day URL Verification: When using Gemini to summarize web pages, parse research papers, or automate web tasks, Chrome now triggers live Safe Browsing checks to protect users against newly generated malicious domains and deceptive redirect chains.
Legacy Chrome Apps officially cut off in Kiosk mode
As we previously highlighted in our ChromeOS 150 coverage, Google laid out a strict sunset roadmap for legacy packaged Chrome Apps. With ChromeOS 151, the other shoe has officially dropped for Kiosk deployments.
- Kiosk Sessions Cut Off: Legacy Chrome Apps no longer launch in Kiosk mode. Organizations that manage digital signage, interactive displays, or student testing kiosks must migrate their workflows to Progressive Web Apps (PWAs).
- Managed Guest & User Sessions: If your organization still relies on force-installed Chrome Apps within standard user sessions or Managed Guest Sessions (MGS), those will continue to work for now as part of Google’s phased transition.
ChromeOS Flex legacy GPU update freeze
For those running ChromeOS Flex on older converted PC and Mac hardware, ChromeOS 151 introduces strict hardware compatibility cutoffs to prevent graphical glitches and system freezes.
- Blocked Hardware: Devices equipped with legacy graphics processors like Intel and AMD GPUs from 2010 and older, and Nvidia GPUs from 2014 and older will no longer receive updates starting with milestone 151.
- Device Status: Affected machines will remain supported on ChromeOS 150 but will be pinned to that version moving forward.
Stricter Incognito URL filtering & enterprise policies
For school IT administrators and enterprise fleet managers, ChromeOS 151 tightens how administrative rules apply across private windows.
- Strict Incognito Blocklists: The URLBlocklist policy is now strictly enforced across Incognito sessions, closing previous loopholes where allowlist configurations could accidentally override restrictions in private tabs.
- Cleaner Wildcard Reporting: Wildcard entries (
*) in URLAllowlist policies are now handled more accurately in internal reporting tools, ensuring status logs reflect targeted permissions rather than blanket approvals.
18 high-priority security fixes
ChromeOS 151 is one of the most security-heavy platform updates we have seen in recent cycles. According to the Google Chrome Releases Stable Channel announcement and Chrome Enterprise Release Notes, Google has resolved 18 CVE-tracked vulnerabilities across core system subsystems:
- Mojo & Window Management: Fixed a critical integer overflow in Mojo (CVE-2026-13281) and a use-after-free vulnerability in the Aura window manager (CVE-2026-15905).
- DOM & WebGL: Resolved use-after-free flaws in DOM (CVE-2026-9126), DOM data validation (CVE-2026-15123), and improper implementation in WebGL (CVE-2026-15127).
- File System & Input: Addressed insufficient policy enforcement in the File System Access API (CVE-2026-12460) and an input handling use-after-free flaw (CVE-2026-15118).
- Credentials & Web Authentication: Patched password data validation bugs (CVE-2026-12446) and Web Authentication use-after-free flaws (CVE-2026-19166).
- Payments, Resources & Extensions: Closed use-after-free flaws in Payments (CVE-2026-19155, CVE-2026-19175), Resources (CVE-2026-19141), and untrusted input validation issues in Extensions (CVE-2026-12456) and Web Workers (CVE-2026-19153).
How to get ChromeOS 151 now
ChromeOS 151 is rolling out starting today. To check if the update is ready for your Chromebook:
- Open your device Settings.
- Select About ChromeOS in the bottom left menu.
- Click Check for updates.
From what we can tell over at cros.tech, most currently-supported devices are getting the update right away. Curiously, the Lenovo Chromebook Plus 14 is left out for the time being. While we’re unsure what the holdup is for that particular device, I’m sure it will be sorted out soon.
SUBSCRIBE TO UPSTREAM
Get Chrome Unboxed delivered straight to your inbox
Upstream is our flagship, curated newsletter with the top stories, most click-worthy deals, giveaways, and trending articles from Chrome Unboxed sent directly to your inbox a few times a week. Join 31,000+ subscribers.

