NEWS

Google Tests Hidden Setting That Could Give Gemini Full Access to Your Mac

A hidden Gemini Desktop setting could grant full Mac file, app and web access without per-action prompts, as Apple moves to restrict that level of access.

Dylan H.

News Desk

October 3, 2026
9 min read
Google Tests Hidden Setting That Could Give Gemini Full Access to Your Mac

Google Is Testing a Setting That Would Let Gemini Run Loose on Your Mac

Google is quietly testing a hidden feature inside the Gemini Desktop app for macOS that, once enabled, could let its AI assistant read, create, modify, or delete any file on the device — not just files in folders a user has explicitly connected — open and operate other applications such as Mail, Safari, and Messages, browse the web, and in some cases take actions without asking for confirmation first. The capability was spotted by independent AI tracker TestingCatalog inside a currently hidden "Additional sandbox options" panel in the Gemini Desktop settings, and reported by BleepingComputer on October 3, 2026. Google has not confirmed the feature publicly, and it is not yet live for general users.

The discovery lands just one day after Apple announced it is tightening controls around macOS's Full Disk Access permission specifically because of the growing risks posed by autonomous AI agents — a timing coincidence that puts Gemini's expanding ambitions on a collision course with the platform it depends on.


Details

AttributeValue
Feature"Additional sandbox options" panel in Gemini Desktop for macOS
Discovered byTestingCatalog (via X/Twitter), reported by BleepingComputer
Disclosure dateOctober 3, 2026
StatusHidden/in testing — not yet enabled for general users; unconfirmed by Google
Scope of access (if enabled)Any file on disk, connected apps (Mail, Safari, Messages), web browsing, autonomous actions
Underlying model (suspected)Next-generation Gemini model, likely tied to upcoming "computer use" capabilities
Related prior featureGemini Spark (desktop/file-organization agent for macOS)
Platform responseApple announced tighter Full Disk Access controls for AI agents, October 2, 2026

What's Actually Being Tested

A hidden permissions panel

According to the reporting, the setting does not appear in the normal Gemini Desktop interface. Testers found it buried in app internals, suggesting Google is still validating the feature internally before any public rollout. When surfaced, a pop-up inside Gemini Desktop reportedly explains the capability directly:

"By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac... Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first."

That is a meaningful shift from the current Gemini Spark model, which operates inside folders a user has explicitly connected to the assistant. The new setting would let Gemini step outside that sandbox entirely and reach the whole filesystem, plus communicate with other installed applications to carry out multi-step tasks on a user's behalf — the hallmark of so-called agentic or computer-use AI.

What safeguards would remain

BleepingComputer's reporting notes that even with the expanded sandbox options enabled, Gemini would reportedly still require explicit, one-time confirmation before:

  • Purchasing products or transferring money
  • Creating a new online account
  • Accepting legal terms on the user's behalf
  • Modifying sensitive personal information

Beyond that narrow list, routine actions — opening files, moving or deleting data, launching apps, browsing sites — could proceed without a prompt once the broader access is granted. Google is reportedly positioning this as similar to the consent model used by other AI coding and computer-use agents, where a user grants broad permission once rather than approving every discrete step.

Why now — Gemini Spark and the push toward "computer use"

This isn't Google's first step toward an agent that operates a Mac like a person would. Gemini Spark, rolled out earlier in 2026, already gives Gemini access to a user's desktop and locally stored files well enough to automatically sort a cluttered Downloads folder into organized directories — performing the task the same way a human user would, by moving files directly on the desktop. Industry observers, including TestingCatalog, believe the expanded sandbox options are a precursor to deeper computer-use features likely powered by a more advanced underlying model, widely expected to be a future Gemini release.

Apple's countermove: tightening Full Disk Access

Separately — but directly relevant — Apple published developer guidance on October 2, 2026 announcing it will add new controls around macOS's Full Disk Access permission, the system-level grant that lets approved software read data across the entire disk, including Mail, Messages, Safari history, and Time Machine backups. Apple explicitly cited the rise of AI agents as the reason, noting that increasingly capable agents make broad, standing file access far riskier than it was when Full Disk Access was originally designed to support backup tools.

Apple's announcement named several agentic AI platforms as part of its concern, including Meta's Muse, a tool called Hermes, and Gemini Spark. The move follows a controversy in which a journalist alleged Meta's Muse app read private messages on a Mac (a claim Meta disputed), and a separate Wired report on a flaw in the ChatGPT Mac app that could have exposed sensitive local data to attackers. Apple's stated fix is to require "very explicit user action" before an app can be granted Full Disk Access going forward, though it has not detailed exactly how the new consent flow will work or when it ships.

Notably, there is no official Apple API for third-party apps to read iMessage history — any assistant that wants that data, including a future Gemini integration with Apple Messages that has reportedly been in testing, would need the kind of broad filesystem access Apple is now moving to restrict.


Impact Assessment

Impact AreaDescription
Data exposureFull filesystem access would expose financial documents, private messages, saved credentials, browser history, and personal files to a cloud-connected AI model if enabled
Reduced friction, reduced visibilityRemoving per-action confirmation prompts improves usability but removes the user's last checkpoint before a destructive or unwanted action occurs
Cross-app blast radiusAccess to Mail, Safari, and Messages means a single compromised or manipulated agent session could touch communications and credentials, not just files
Prompt-injection riskAn agent with standing file/app/web access is a larger target for prompt-injection attacks embedded in web pages, documents, or emails it processes
Platform/vendor tensionApple's Full Disk Access tightening directly targets the category of access Gemini is testing, suggesting friction or redesign ahead for Google's rollout
Industry patternMuse (Meta), Hermes, and the ChatGPT Mac app flaw show this is a sector-wide risk, not a Gemini-specific defect

Recommendations

For macOS users considering AI desktop agents

  • Do not enable "full access" or "additional sandbox" style settings in any AI desktop app until the vendor publishes a clear, specific explanation of what is accessed and when
  • Treat Full Disk Access grants as equivalent to handing over your entire personal archive — only approve them for software you trust implicitly, and review System Settings → Privacy & Security → Full Disk Access periodically to revoke access from apps you no longer use
  • Keep sensitive documents (tax records, credentials, legal files) outside any folder explicitly connected to an AI assistant, and avoid granting disk-wide access as a shortcut
  • Watch for Apple's forthcoming Full Disk Access changes and update AI agent apps promptly once new consent flows ship

For IT and security teams managing fleets of Macs

  • Inventory which endpoints have AI desktop agents (Gemini Spark, ChatGPT desktop, Muse, Hermes, or similar) installed and whether Full Disk Access has been granted
  • Use MDM profiles to restrict or audit Full Disk Access (com.apple.TCC configuration profiles) for unapproved applications, pending Apple's updated controls
  • Add agentic AI permission changes to vulnerability/change-management tracking — a silent capability expansion inside an existing app (as seen here) can bypass normal software-approval review
  • Monitor vendor release notes for Gemini Desktop, since Google has not confirmed a timeline and the feature could ship with little advance warning

For Google and Gemini Desktop testers

  • If the hidden setting appears in your build, treat it as pre-release/unstable — do not enable it on a primary work or personal device
  • Report unexpected file, app, or network activity from Gemini Desktop through official feedback channels rather than assuming it is expected behavior

Key Takeaways

  1. A hidden "Additional sandbox options" setting discovered in Gemini Desktop for macOS could let Gemini access any file on disk, control apps like Mail and Safari, browse the web, and act without per-step confirmation.
  2. The feature is not yet live and unconfirmed by Google — it was found through internal app interface elements, not an official announcement.
  3. Some high-risk actions (purchases, account creation, legal agreements, sensitive-data changes) would reportedly still require explicit confirmation even with broader access enabled.
  4. The feature builds on Gemini Spark, Google's existing desktop file-organization agent, and is believed to anticipate more advanced "computer use" capabilities in a future Gemini model.
  5. Apple announced tighter Full Disk Access controls on October 2, 2026 — one day before this report — explicitly citing AI agent risk, naming Gemini Spark alongside Meta's Muse and Hermes.
  6. Users and IT teams should audit existing Full Disk Access grants now and avoid enabling broad, standing AI agent permissions until vendors publish clear consent and data-handling details.

Sources