Google is rolling out ChromeOS 151 (version 16733.48.0, browser version 151.0.7922.141) to Chromebooks and ChromeOS Flex devices on the Stable channel.
This update adds a bookmark bar auto-hide option, real-time Safe Browsing for Gemini sessions, ends support for legacy Chrome Apps in Kiosk mode, introduces hardware cutoffs for older ChromeOS Flex devices, tightens enterprise policy enforcement, and addresses 18 security vulnerabilities.
This is one of the most security-focused ChromeOS updates in recent releases.
ChromeOS 151 Adds Bookmark Bar Auto-Hide and Gemini Safe Browsing #
ChromeOS 151 adds new controls for bookmark bar visibility under Settings and then Appearance. If Chrome sees that you rarely use the bookmark bar on the New Tab page, it can now hide it automatically to give you more vertical space.
If the bar is hidden because of low usage, Chrome shows a small notification so you can bring it back with one click. Administrators in schools and businesses can keep the bar visible for everyone by using the updated BookmarkBarEnabled policy. Google has added real-time Safe Browsing protection to Gemini sessions in Chrome. When you use Gemini to summarize web pages, read research papers, or automate web tasks, Chrome now checks for new malicious domains and deceptive redirects in real time.
ChromeOS 151 Ends Kiosk Chrome Apps and Freezes Updates for Older Flex Devices #
As outlined in the ChromeOS 150 rollout, ChromeOS 151 ends support for legacy packaged Chrome Apps in Kiosk mode.
Legacy Chrome Apps no longer launch in Kiosk sessions, so organizations managing digital signage, interactive displays, or student testing kiosks must migrate those workflows to Progressive Web Apps.
Force-installed Chrome Apps still work in regular user sessions and Managed Guest Sessions for now, as Google continues its phased transition.
CChromeOS 151 sets new hardware cutoffs for ChromeOS Flex on older PCs and Macs. Devices with older graphics processors, including Intel and AMD GPUs from 2010 or earlier and Nvidia GPUs from 2014 or earlier, will stop getting updates starting with this release. These machines will stay on ChromeOS 150 and will not receive future updates.
ChromeOS 151 Tightens Incognito Policies and Fixes 18 Security Flaws #
ChromeOS 151 makes administrative rules stricter in private windows for school IT and enterprise managers. The URLBlocklist policy now applies fully in Incognito sessions, closing loopholes where allowlist settings could bypass restrictions in private tabs. Wildcard entries in URLAllowlist policies are now reported more accurately in internal tools.
Google fixed 18 security vulnerabilities in core system components with ChromeOS 151. These include a critical integer overflow in Mojo (CVE-2026-13281), a use-after-free bug in the Aura window manager (CVE-2026-15905), use-after-free issues in DOM (CVE-2026-9126), DOM data validation (CVE-2026-15123), and a WebGL implementation bug (CVE-2026-15127).
Other fixes address policy enforcement gaps in the File System Access API (CVE-2026-12460), an input handling use-after-free bug (CVE-2026-15118), password data validation issues (CVE-2026-12446), Web Authentication use-after-free bugs (CVE-2026-19166), and similar flaws in Payments (CVE-2026-19155, CVE-2026-19175), Resources (CVE-2026-19141), Extensions (CVE-2026-12456), and Web Workers (CVE-2026-19153).
Availability and Device Rollout #
ChromeOS 151 is available starting today. To check for the update:
- Open your device Settings.
- Select About ChromeOS in the bottom-left menu.
- Click Check for updates.
ChromeOS 151 is rolling out now, and Chrome Unboxed says most supported devices are getting it immediately. The Lenovo Chromebook Plus 14 is not included yet, and there is no explanation for the delay.
ChromeOS Flex devices with the affected legacy GPUs will not get the update and will stay on ChromeOS 150.