I have a debian 12 with Unattended Upgrades as a work machine, and it works surprisingly well (I use Arch BTW) - it is probably the simplest way for you to be sure their browser stays up-to-date & keep them safe on this side
Issue with these updates is they happen "behind" and may need a reboot ; this is the only moment I found Debian to misbehave, decide to reboot & I get it when I see the machine updating some component before rebooting again
So this is the full extend of the training to give: in case of doubt, reboot.
I think gnome is perfect in that context also, the lack of Menu is just one hit on the Meta key away, which, if you trim down the install to their exact need will be accessible, confortable.
In my case, The rollback feature bricked its onw disk because on a 30g system partition, an install with a separate home partition (not included in the backups) will drown itself in factory settings backups.
It's a great feature. Give it ample space and trim down on the all the snapshots afterwards.