Skip to content

Security1 publisher2 min readPublished

Hidden Gemini Desktop setting would let Google's agent read, change and delete any Mac file

Google is testing a Gemini Desktop option that could let its agent alter any Mac file and act through Mail, Safari and Messages without asking first. Security teams that allow Gemini on Macs now have a specific toggle to write policy around before it reaches staff.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Hidden Gemini Desktop setting would let Google's agent read, change and delete any Mac file
Photo: testingcatalog.com

What happened

  • TestingCatalog found references to the setting, labelled "Additional sandbox options," in the Gemini Desktop app and posted them on X.
  • Access would extend past the folders a user has explicitly connected to Gemini, reaching files anywhere on the machine.
  • Gemini would still ask before buying products, transferring money, creating online accounts, accepting legal terms or changing sensitive personal information.
  • The setting appears to belong to Google's wider computer-use plans for Gemini, covering files, websites and native apps beyond the chat window.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision BleepingComputer expects a Claude-style opt-in granted by the individual user, so organisations that permit Gemini Desktop have to decide whether staff may enable these options before the toggle reaches them.
  • constraint Apple is weighing limits on agent access to personal Mac files, so what Google's option can actually reach on macOS may be set by Apple as much as by Google.
  • precedent With Gemini moving toward the permission model BleepingComputer compares to Claude's, desktop agents with file and app reach become a product category that a security policy has to name explicitly.

Everything public comes from hidden references in the Gemini Desktop app, as described by BleepingComputer [1]. The feature is not live and Google has not confirmed it [2]. An attacker has nothing to use today [2]. The interface copy is plain about what it is for: "By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac," the hidden text reads, according to BleepingComputer [6].

According to BleepingComputer, the confirmation prompts would cover money, accounts, legal terms and sensitive personal data [8]. Deleting a file is not on that list. Neither is sending through Mail or Messages, the actions the hidden pop-up says Gemini could take [5][1].

Those two gaps are where a bad instruction turns into an incident. A deletion destroys data on disk. A sent message reaches its recipients from the user's real account, under the user's name [1].

With Safari in reach and permission to act without asking, the agent would read text written by strangers [5][7]. BleepingComputer's report does not say how Gemini would treat instructions found inside that text, or inside the files and messages it opens [2].

Timing and model are both open. BleepingComputer says it is unclear when Google will roll out what the report calls Full Access, or which Gemini model would run it [10].

What to watch

  • Google confirming the feature, a rollout date for Full Access, or the Gemini model that would power it.
  • Whether Google ships controls that let organisations block or limit the sandbox options centrally, separate from the user's own opt-in.
  • Apple's decision on restricting AI agent access to personal files and data on macOS.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories