Google tests hidden Gemini Desktop broader Mac access
An unreleased Gemini Desktop option could give Google’s Mac agent broader file, app, and web access, with some sensitive actions still confirmed.
Google is testing a hidden setting in the Gemini Desktop app for macOS, based on interface references rather than an official announcement. One report names the control “Additional sandbox options,” while a later account describes a Full Access permission; if enabled, Gemini could read, create, modify, or delete files—outside folders a user connected, or across a Mac, depending on the source—and act through apps such as Mail, Safari, and Messages, sometimes without asking first. Coverage also says the agent could reach sites and APIs where the user is already signed in or use the network without approving every connection, and later reporting warns that prompt injection from web pages, documents, or email could steer those privileges and create data-theft risk. The option is not publicly released; Google has not confirmed a model or rollout date, links to a future Gemini 4 are called speculative or unconfirmed, and one source says testing is limited to trusted testers. Sources do not fully agree on safeguards: all mention confirmation for purchases, two include money transfers, and two also list account creation, accepting legal terms, and changes to sensitive personal information. Separately, Apple is reported to be considering limits on AI agents that access personal Mac data.
- A hidden Gemini Desktop control on macOS, called “Additional sandbox options” and later described as Full Access, was found in interface text, not via an official Google announcement.
- If enabled, Gemini could read, create, modify, or delete files beyond folders a user connected; later reports describe that reach as across or anywhere on a Mac.
- The agent could control apps such as Mail, Safari, and Messages and use already signed-in sites, APIs, or other network connections, sometimes without a prompt for every action.
- Sources say some high-impact actions would still need confirmation; they agree on purchases but differ on money transfers, account creation, legal terms, and sensitive personal-data changes.
- The feature is not publicly released. Google has not confirmed a model or date, Gemini 4 links are unconfirmed or speculative, and one report says it is in trusted testing only.
- Later coverage warns that prompt injection from web pages, documents, or email could steer a broadly privileged agent and raise data-theft risk.
- Apple is separately reported to be considering limits on AI agents accessing personal Mac data.
- One outlet credits TestingCatalog with finding the setting in a recent Gemini Desktop test build.
Coverage timelineoldest first · each row is one article
- · 5d agoGoogle Gemini could soon get full access to your Mac’s files, apps and the web
BleepingComputer· 55
Google is testing Gemini Desktop controls that could access Mac files, apps, and the web with fewer prompts.
- · 3d agoGoogle Gemini to Gain Full Computer Access With New Permission
GBHackers· 63
Google is testing a hidden Gemini Desktop option that could give its agent broad file, app, and network access on Macs.
- · 3d agoGoogle Gemini Will Soon Get Full Access Permission to Use Your Computer
Cyber Security News· 58