Google is reportedly testing a new Gemini Desktop feature that could give its AI agent extensive control over a user’s Mac.
This includes access to files, interaction with installed applications, and network communication, all with fewer prompts requiring user approval for each action. Currently, Google has not publicly released this capability, and it has not confirmed a rollout date.
AI-news tracker TestingCatalog identified this feature in a recent build of Gemini Desktop, under a hidden setting called “Additional sandbox options.”
The warning text indicates that enabling this setting would significantly expand Gemini’s current sandbox restrictions, allowing for more autonomous workflows on the computer.
Gemini Gain Full Computer Access
According to the exposed interface text, Gemini could potentially read, create, modify, or delete files anywhere on a Mac, not just within folders specifically linked to the assistant.
This capability might also extend to files saved locally by other users on the same device. This broad access increases the risk of erroneous prompts, malicious instructions, or compromised AI sessions.
The proposed permission set also includes cross-application control. Gemini might communicate with macOS applications like Mail, Safari, and Messages and execute actions through them.
In practice, an AI agent with these privileges could collect information from an open browser session, organize files, draft communications, navigate authenticated web services, or automate multi-step workflows across both local and cloud applications.
Google’s existing Gemini Desktop features already include screen-context sharing, editing across open applications, and local-folder connectivity through Gemini Spark.
This new hidden configuration suggests a shift from context-aware assistance to a more general-purpose desktop agent with broader operating-system interaction.
This setting could also enable Gemini to send and receive network data without requiring approval for each connection. The interface wording specifically mentions access to websites, APIs, and services where a user is already signed in.
This creates a significant security risk, as authenticated browser sessions and desktop applications often have access to sensitive information such as email, corporate portals, cloud storage, developer platforms, and financial services.
For cybersecurity experts, the main concern is not just file access but the combination of local access, application control, and network connectivity. An agent that can read documents, browse the internet, access logged-in services, and transmit data externally poses a higher risk for prompt injection attacks, credential theft, malicious extensions, and social engineering campaigns.
The interface text suggests that Gemini would still ask for confirmation before high-impact actions, such as making purchases, creating accounts, accepting legal terms, transferring money, or changing sensitive personal information.
However, the specific definition of “sensitive” actions, the granularity of approval prompts, and the details regarding logging or rollback controls have not been disclosed.
Organizations should view the reported capability as a potential future security risk posed by agentic AI, rather than an active feature of Gemini.
If this feature is implemented, security teams will need to evaluate endpoint permissions, data-loss prevention controls, browser session exposure, application allowlisting, and the risk of indirect prompt injection through files, webpages, emails, and messages.
For now, the “Full Access” functionality appears to be in trusted testing only. Google has not announced details on availability, supported operating systems beyond Mac, pricing, or the model that will drive this feature; reports linking it to Gemini 4 remain speculative.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

