Google Gemini Desktop App May Grant AI Full Access to User Macs
A hidden setting in Google's Gemini Desktop app could soon allow the AI to read files, control applications, and access network services on a user's Mac, raising significant privacy and security concerns.

Google's Gemini Desktop application is reportedly developing a new "Full Access" permission that would grant the AI assistant extensive control over a user's Mac. This feature, discovered within a hidden "Additional sandbox options" setting, could allow Gemini to read, modify, and delete files anywhere on the system, control other applications like Mail and Safari, and communicate freely over the network.
This expansion of Gemini's capabilities moves beyond its current role as a conversational AI, enabling it to interact with the local environment in ways typically reserved for trusted desktop software. The potential for Gemini to access files outside of explicitly connected folders, and even those belonging to other users on the same device, highlights the significant privacy implications of this development.
Beyond file access, the "Full Access" permission could enable Gemini to interact with other installed programs. This means the AI could potentially draft emails, send messages, or perform actions within applications like web browsers and messaging clients, significantly increasing its utility for complex, multi-step tasks.
Furthermore, the ability for Gemini to send and receive data over the network without explicit approval for each connection raises concerns about its interaction with external services. This could allow the AI to access websites, cloud services, and authenticated accounts, potentially exposing sensitive information or enabling unauthorized actions.
While this feature promises to enhance Gemini's usefulness for tasks such as research, document organization, and workflow automation, it also introduces substantial cybersecurity risks. An AI agent with such broad access becomes a high-value target for attackers, who could exploit vulnerabilities like prompt injection to manipulate the AI into exfiltrating sensitive data or performing malicious actions.
Google reportedly plans to implement additional confirmation steps for highly sensitive actions, such as making purchases or modifying personal information. This suggests a tiered approach to permissions, where critical operations would still require explicit user consent, mitigating some, but not all, of the associated risks.
Organizations are strongly advised to approach such AI agent permissions with caution. Security teams should consider restricting access to sensitive data, avoiding the enablement of broad permissions on unmanaged devices, and enforcing least-privilege principles to minimize potential exposure.
The "Full Access" feature is currently hidden and has not been officially announced by Google. Its potential integration with future Gemini versions, such as Gemini 4, remains speculative, but its development signals a significant shift in how AI assistants may interact with user devices.