Privacy News Google Gemini Will Soon Get Full Access Permission to Use Your Computer

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
Google’s Gemini Desktop app may soon introduce a “Full Access” permission that would let the AI assistant read files, control applications, access network services, and take action across a user’s Mac.

The capability appears to be part of a hidden “Additional sandbox options” setting discovered in a recent version of the Gemini Desktop app. The reported feature would significantly expand Gemini’s computer-use capabilities beyond its existing role as a conversational AI assistant.
If enabled, the permissions could let Gemini interact with a user’s local environment in ways normally reserved for trusted desktop applications, including accessing files outside explicitly connected folders.

According to the discovered permission text, enabling additional sandbox options may allow Gemini to read, create, modify, or delete files anywhere on a Mac.

Apple also plans to add stronger controls to Full Disk Access in macOS, warning that the powerful permission can expose a user’s most private data as AI agents become more capable.

Google Gemini Computer Access
This could include files outside the folders connected to Gemini, as well as files belonging to other people stored on the same device. The setting could also permit the application to communicate with other installed programs, such as Mail, Safari, and Messages, and perform actions through those applications.

The permission model may also enable Gemini to send and receive data over the network without requesting approval for every connection.

In practice, that could allow the AI agent to access websites, APIs, cloud services, and accounts where the user is already signed in. Such access could make Gemini more useful for multi-step tasks, including researching information, organizing documents, drafting emails, completing web-based workflows, and interacting with enterprise tools.

However, the feature introduces important cybersecurity and privacy concerns. An AI agent with unrestricted access to files, browser sessions, network services, and messaging applications would become a high-value target for attackers.

A prompt injection attack, malicious web page, compromised browser session, or unsafe instruction could potentially influence an agent with broad permissions. For example, a user may ask Gemini to summarize documents from a folder.

If Gemini is simultaneously allowed to browse the web and communicate with other applications, a malicious webpage could attempt to manipulate the agent into collecting sensitive files, opening authenticated services, or sending data externally.
The risk is not limited to malicious AI prompts; it also includes compromised websites, untrusted documents, deceptive emails, and vulnerable third-party applications. Google reportedly plans to keep additional confirmation requirements for particularly sensitive actions.

Gemini would still ask for user approval before purchasing products, creating accounts, accepting legal terms, or modifying sensitive personal information. This indicates that Google may use a tiered permission approach, separating ordinary computer-use actions from higher-risk decisions.

The full-access option is currently hidden, and Google has not formally announced it. TestingCatalog suggested the computer-use capabilities could relate to a future Gemini 4-powered experience, though this remains unconfirmed.

Organizations should treat such AI-agent permissions carefully when they become available. Security teams should restrict access to sensitive folders, avoid enabling broad permissions on unmanaged devices, apply least-privilege controls, and closely review what data and applications an AI assistant can access.
 
Hi Brownie2019, the security concern is legitimate, but “will soon get full access” is ahead of the evidence. What has actually been found is an unreleased “Additional sandbox options” setting associated with trusted testing. Google has neither announced it nor provided a release date, and the suggested Gemini 4 connection is speculation. The more accurate headline would be: Google is testing broader Gemini Desktop permissions on macOS.

Google’s current documentation says Gemini Spark can view only files and directories deliberately added as Connected Folders. Those files can nevertheless be edited, shared or deleted, so even the released model deserves care. The reported setting would remove much of that useful containment by allowing work beyond selected folders and across other applications.

It is also worth separating two layers:

  • Gemini’s setting could relax its own sandbox and approval policy.
  • macOS permissions such as Full Disk Access, Automation, Accessibility and screen access still require separate operating-system authorization. An application cannot simply award these permissions to itself.

If all those permissions were granted, however, the practical risk would be considerable. Prompt injection in a webpage, email or document could potentially turn the agent into a “confused deputy”: it has the user’s authority and may be manipulated into using it for somebody else. Confirmation prompts for purchases and legal decisions help, but they do not protect files that the agent can routinely read, overwrite or disclose.

For anyone testing this type of feature, I would use:

  • a separate standard macOS account, not the everyday administrator account;
  • narrowly selected folders containing copies rather than irreplaceable originals;
  • no access to browser profiles, password stores, Mail, Messages, SSH keys or broad cloud-drive roots;
  • current, versioned backups;
  • regular review of System Settings → Privacy & Security, especially Full Disk Access, Accessibility, Automation, Files and Folders, and screen recording.

Apple’s planned tightening of Full Disk Access is sensible, but it is a broader response to increasingly autonomous desktop agents—not confirmation that this Gemini capability is about to ship. For now, this is a credible capability under testing, not an observed compromise and not yet a released “master key” for every Mac. Google’s current Gemini Spark documentation and the original TestingCatalog report make that boundary fairly clear.

Sources
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top