Google Gemini to Gain Full Computer Access With New Permission
Google is testing a hidden Gemini Desktop option that could give its agent broad file, app, and network access on Macs.
TestingCatalog found a hidden “Additional sandbox options” setting in a recent Gemini Desktop build that would expand the agent beyond its current sandbox. Interface text indicates Gemini could read, create, modify, or delete files across a Mac, control apps such as Mail, Safari, and Messages, and reach sites and APIs where the user is already signed in. Google has not announced a release or the driving model; links to Gemini 4 are described as speculative. The feature is reported to be in trusted testing only, with confirmation still required for high-impact actions such as purchases or money transfers.
- Hidden Full Access setting seen in a Gemini Desktop test build.
- Could read or change files and control Mail, Safari, and Messages.
- Network access to signed-in sites raises prompt-injection and data-theft risk.
- Not publicly released; Google has not confirmed a rollout date.
Full article636 words · extracted from gbhackers.com · click to collapse
Google is reportedly testing a new Gemini Desktop feature that could give its AI agent extensive control over a user’s Mac.
This includes access to files, interaction with installed applications, and network communication, all with fewer prompts requiring user approval for each action. Currently, Google has not publicly released this capability, and it has not confirmed a rollout date.
AI-news tracker TestingCatalog identified this feature in a recent build of Gemini Desktop, under a hidden setting called “Additional sandbox options.”
The warning text indicates that enabling this setting would significantly expand Gemini’s current sandbox restrictions, allowing for more autonomous workflows on the computer.
Gemini Gain Full Computer Access
According to the exposed interface text, Gemini could potentially read, create, modify, or delete files anywhere on a Mac, not just within folders specifically linked to the assistant.
This capability might also extend to files saved locally by other users on the same device. This broad access increases the risk of erroneous prompts, malicious instructions, or compromised AI sessions.
The proposed permission set also includes cross-application control. Gemini might communicate with macOS applications like Mail, Safari, and Messages and execute actions through them.
In practice, an AI agent with these privileges could collect information from an open browser session, organize files, draft communications, navigate authenticated web services, or automate multi-step workflows across both local and cloud applications.
Google’s existing Gemini Desktop features already include screen-context sharing, editing across open applications, and local-folder connectivity through Gemini Spark.
This new hidden configuration suggests a shift from context-aware assistance to a more general-purpose desktop agent with broader operating-system interaction.
This setting could also enable Gemini to send and receive network data without requiring approval for each connection. The interface wording specifically mentions access to websites, APIs, and services where a user is already signed in.
This creates a significant security risk, as authenticated browser sessions and desktop applications often have access to sensitive information such as email, corporate portals, cloud storage, developer platforms, and financial services.
— 🚨 AI News | TestingCatalog (@testingcatalog) October 2, 2026GOOGLE 🔥: Gemini Desktop will have a "Full Access" permission for computer use, allowing it to access any file and run any app on your desktop.
> A new "Additional sandbox options" setting has been added to the recent Gemini Desktop app (Still hidden).
> "By enabling… pic.twitter.com/N4ZQTzff11
For cybersecurity experts, the main concern is not just file access but the combination of local access, application control, and network connectivity. An agent that can read documents, browse the internet, access logged-in services, and transmit data externally poses a higher risk for prompt injection attacks, credential theft, malicious extensions, and social engineering campaigns.
The interface text suggests that Gemini would still ask for confirmation before high-impact actions, such as making purchases, creating accounts, accepting legal terms, transferring money, or changing sensitive personal information.
However, the specific definition of “sensitive” actions, the granularity of approval prompts, and the details regarding logging or rollback controls have not been disclosed.
Organizations should view the reported capability as a potential future security risk posed by agentic AI, rather than an active feature of Gemini.
If this feature is implemented, security teams will need to evaluate endpoint permissions, data-loss prevention controls, browser session exposure, application allowlisting, and the risk of indirect prompt injection through files, webpages, emails, and messages.
For now, the “Full Access” functionality appears to be in trusted testing only. Google has not announced details on availability, supported operating systems beyond Mac, pricing, or the model that will drive this feature; reports linking it to Gemini 4 remain speculative.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.