NEWS

Google Gemini Could Soon Get Full Access to Your Mac's Files, Apps, and the Web

A hidden setting in Gemini's macOS app could let the AI read, edit, and delete any file, control native apps, and browse the web without asking first.

Dylan H.

News Desk

October 4, 2026
8 min read
Google Gemini Could Soon Get Full Access to Your Mac's Files, Apps, and the Web

Google Is Testing Full System Access for Gemini on macOS

Google appears to be building a dramatically expanded permission model for Gemini on macOS, one that would let the assistant read, create, modify, or delete files anywhere on a Mac, control native apps like Mail, Safari, and Messages, browse the web, and carry out actions without asking for confirmation every time. The capability was spotted by researcher TestingCatalog, who found a hidden "Additional sandbox options" setting buried in the code of the Gemini Desktop app. The feature is not yet live, has not been officially confirmed by Google, and its rollout timeline remains unknown as of October 3, 2026.

A pop-up string uncovered inside the app reportedly warns users plainly about the trade-off they would be making: "By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac... Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first."


Details

AttributeValue
Feature"Additional sandbox options" (hidden setting)
ProductGemini Desktop app for macOS
VendorGoogle
Discovered byTestingCatalog (via X/Twitter code analysis)
Scope of accessFile system (read/write/delete), native apps, web browsing
StatusNot live; unconfirmed by Google; no announced timeline
Related featureGemini Spark (already shipped, folder-scoped)
Industry contextApple tightening macOS Full Disk Access controls (announced October 2, 2026)

What's Changing

Gemini on the Mac already has a more limited version of local access through Gemini Spark, a feature Google rolled out earlier in 2026. Spark lets users explicitly add folders — such as the desktop, Downloads, Documents, or Photos — to a "Connected folders" list, after which Gemini can view and edit files inside those directories. Even with that access granted, Spark is designed to ask for explicit confirmation before permanently deleting a file or sharing it with a third party.

The newly discovered "Additional sandbox options" setting appears to remove that folder-by-folder scoping entirely. Rather than opting individual directories in, the toggle would open Gemini's reach to any file on the device, plus the ability to drive native macOS applications directly and perform multi-step actions on the web — all characteristics of the "computer-use" style agents that Google, OpenAI, and Anthropic have each been racing to ship throughout 2026.

How the Expanded Permission Model Would Work

Based on the strings uncovered inside the app, the feature is framed as an explicit, opt-in sandbox relaxation rather than a default-on change. Analysis from Threat Radar of the same code paths indicates the expanded mode would let Gemini interact with apps such as Mail, Safari, and Messages well beyond simple file read access — effectively letting the model act as the user inside those applications to send messages, open pages, or move content between apps.

Google has reportedly built in some guardrails that would persist even with the sandbox opened up. According to the reporting, Gemini would still be required to pause and ask for explicit confirmation before:

  • Purchasing products or completing any transaction involving money
  • Creating a new online account on the user's behalf
  • Accepting legal terms or agreements
  • Modifying sensitive personal information

Outside of those carved-out categories, however, the pop-up language — "Gemini may be permitted to take actions without asking for your permission first" — signals that routine file operations, app interactions, and web actions could proceed autonomously once a user flips the setting on.

Why This Is Surfacing Now

The discovery lands in the middle of a broader industry reckoning over desktop AI agents and file access. On October 2, 2026, Apple announced it would introduce additional controls around macOS's Full Disk Access permission, citing risk from AI agents directly. Apple's statement noted that "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems — including files, mail, messages, and even browsing history — without users' full knowledge and understanding."

That announcement followed a specific controversy involving Meta's Muse desktop agent: journalist Jason Aten reported that Muse appeared to know the contents of his private Messages conversations despite his not having knowingly granted that access, a claim Meta disputed. Muse, Hermes, and Gemini Spark are cited together as examples of the fast-growing category of third-party AI agents requesting deep macOS system access, and Apple's tightening of Full Disk Access is widely read as a direct response to that trend — one that could constrain exactly how far Google is able to take Gemini's new sandbox mode once it ships.


Impact Assessment

Impact AreaDescription
Data exposureFull file-system access would let Gemini read financial records, personal photos, correspondence, and credentials stored in plaintext or config files anywhere on disk
App-layer riskDirect control of Mail, Safari, and Messages raises the risk of unintended disclosure, account changes, or message sends without a clear audit trail
Platform tensionApple's own Full Disk Access tightening could restrict or delay how Google implements the feature on macOS
Enterprise exposureOrganizations allowing Gemini Desktop on managed Macs may unknowingly expand their attack surface if the sandbox setting is enabled by end users
Trust modelRemoving per-action confirmation shifts risk from "informed consent each time" to "one-time broad grant," a pattern security researchers have flagged across the computer-use agent category in 2026
Unconfirmed statusBecause Google has not announced the feature, there is currently no published security documentation, data-handling policy, or opt-out guidance for end users

Recommendations

For Mac Admins and IT Teams

  • Treat the Gemini Desktop app as a managed software title requiring explicit approval before deployment on company-owned Macs, pending Google's official documentation of the sandbox feature
  • Use MDM profiles to restrict or monitor Full Disk Access grants, consistent with Apple's own direction announced October 2
  • Audit which endpoints already have Gemini Spark's "Connected folders" enabled and confirm the scope matches business need

For Security Teams

  • Add Gemini Desktop (and comparable agents such as Muse and Hermes) to AI-agent inventories and monitor vendor release notes for the sandbox toggle going live
  • Evaluate logging and DLP coverage for scenarios where an AI agent, not a human, initiates file access or app actions on an endpoint
  • Revisit incident-response playbooks to account for AI-agent-initiated activity as a distinct event category, separate from standard user or malware activity

For Individual Users

  • Do not enable "Additional sandbox options" (or any equivalent broad-access toggle) until Google publishes clear, official documentation of what the setting does and how data is handled
  • If using Gemini Spark today, keep "Connected folders" limited to only the directories genuinely needed, and avoid adding folders containing financial records, credentials, or sensitive correspondence
  • Review macOS Full Disk Access entries periodically (System Settings → Privacy & Security) and revoke access for any app that no longer needs it

Key Takeaways

  1. A hidden "Additional sandbox options" setting discovered inside the Gemini Desktop app by researcher TestingCatalog would let Gemini access any file, control native Mac apps, and browse the web largely without per-action confirmation.
  2. The feature is not yet live and has not been officially confirmed by Google; no rollout date or model has been announced.
  3. It builds on Gemini Spark, Google's existing folder-scoped local-file feature, but removes the current folder-by-folder opt-in scoping.
  4. Reported safeguards would still require confirmation for purchases, money transfers, account creation, legal agreements, and sensitive personal-data changes — but routine file and app actions could proceed autonomously.
  5. The discovery coincides with Apple's October 2, 2026 announcement tightening macOS Full Disk Access controls specifically to address AI agent risk, following a disputed report that Meta's Muse agent accessed private Messages content.
  6. Users and admins should withhold broad access grants to any desktop AI agent, including Gemini, until vendors publish clear data-handling and consent documentation.

Sources