Google’s Gemini Desktop app may soon introduce a “Full Access” permission that would let the AI assistant read files, control applications, access network services, and take action across a user’s Mac.
The capability appears to be part of a hidden “Additional sandbox options” setting discovered in a recent version of the Gemini Desktop app. The reported feature would significantly expand Gemini’s computer-use capabilities beyond its existing role as a conversational AI assistant.
If enabled, the permissions could let Gemini interact with a user’s local environment in ways normally reserved for trusted desktop applications, including accessing files outside explicitly connected folders.
According to the discovered permission text, enabling additional sandbox options may allow Gemini to read, create, modify, or delete files anywhere on a Mac.
Apple also plans to add stronger controls to Full Disk Access in macOS, warning that the powerful permission can expose a user’s most private data as AI agents become more capable.
Google Gemini Computer Access
This could include files outside the folders connected to Gemini, as well as files belonging to other people stored on the same device. The setting could also permit the application to communicate with other installed programs, such as Mail, Safari, and Messages, and perform actions through those applications.
The permission model may also enable Gemini to send and receive data over the network without requesting approval for every connection.
In practice, that could allow the AI agent to access websites, APIs, cloud services, and accounts where the user is already signed in. Such access could make Gemini more useful for multi-step tasks, including researching information, organizing documents, drafting emails, completing web-based workflows, and interacting with enterprise tools.
However, the feature introduces important cybersecurity and privacy concerns. An AI agent with unrestricted access to files, browser sessions, network services, and messaging applications would become a high-value target for attackers.
A prompt injection attack, malicious web page, compromised browser session, or unsafe instruction could potentially influence an agent with broad permissions. For example, a user may ask Gemini to summarize documents from a folder.
If Gemini is simultaneously allowed to browse the web and communicate with other applications, a malicious webpage could attempt to manipulate the agent into collecting sensitive files, opening authenticated services, or sending data externally.
The risk is not limited to malicious AI prompts; it also includes compromised websites, untrusted documents, deceptive emails, and vulnerable third-party applications. Google reportedly plans to keep additional confirmation requirements for particularly sensitive actions.
Gemini would still ask for user approval before purchasing products, creating accounts, accepting legal terms, or modifying sensitive personal information. This indicates that Google may use a tiered permission approach, separating ordinary computer-use actions from higher-risk decisions.
The full-access option is currently hidden, and Google has not formally announced it. TestingCatalog suggested the computer-use capabilities could relate to a future Gemini 4-powered experience, though this remains unconfirmed.
Organizations should treat such AI-agent permissions carefully when they become available. Security teams should restrict access to sensitive folders, avoid enabling broad permissions on unmanaged devices, apply least-privilege controls, and closely review what data and applications an AI assistant can access.