Gemini Desktop may get full access to Mac files and apps

Gemini Desktop may get full access to Mac files and apps

Google appears to be preparing a mode for its Gemini Desktop app on macOS that would let the AI assistant reach any file on the machine, open and operate apps, browse the web, and act without asking for approval each time.

The feature has not launched, and Google has not confirmed it. It was spotted by TestingCatalog, which posted on X about Google testing desktop control for Gemini and about references to a hidden setting called "Additional sandbox options."

Beyond connected folders

At the moment, Gemini can only work with folders the user has explicitly connected to it. The hidden setting would remove that limit. Once switched on, Gemini could read, create, modify and delete files anywhere on the computer.

The access would also reach other applications. A pop-up inside Gemini Desktop says the assistant could communicate with apps such as Mail, Safari and Messages and carry out actions through them.

The hidden interface describes the option in plain terms: "By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac."

It also includes a warning: "Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first."

Some actions still need approval

The mode would not give Gemini full control with no checks at all. The experience is expected to resemble Anthropic's Claude, where the user explicitly grants the assistant permission to operate the computer.

Even with the broader access enabled, Gemini would still ask for confirmation before it:

  • buys products or transfers money
  • creates an online account
  • accepts legal terms on the user's behalf
  • modifies sensitive information about the user

The setting appears to belong to Google's wider computer-use plans for Gemini. The aim is for the assistant to work across files, websites and native apps, not just inside a chat window.

Google has not said when the feature, referred to as Full Access, might roll out or which Gemini model would run it.

Apple may have a say

How the feature works in practice may depend on Apple. The company is reportedly considering measures that would make it harder for AI agents to access personal files and data on the Mac. If Apple goes ahead, the reach of a mode like this could end up narrower than the hidden interface suggests.

Our Take

For security teams and privacy-minded users, the important detail is the shift in default trust. Gemini currently works with folders the user has chosen. The tested mode would let it reach the whole file system and talk to mail and messaging apps, with some actions taken without a prompt. That is a much larger attack surface for one piece of software.

The list of actions that still need confirmation is useful, but it is short. Deleting files, reading mail or sending messages through Messages are not on it, at least based on what has surfaced so far. That gap is worth watching closely once Google publishes official details.

This also fits a pattern we have covered repeatedly. Research has shown that AI agents keep data access after their tasks are finished, and that agent tools can leak screenshots to public repositories. Separately, the SalesBleed flaws showed how attackers can hijack enterprise AI agents. An assistant with broad desktop rights could become an attractive target for similar abuse.

Organisations that manage Macs may want to check whether they can control or block such settings before the feature ships. It is also worth watching whether Apple's reported restrictions on AI agents arrive first, and how Google adjusts if they do.