"By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac," Google explains in the hidden interface.
TestingCatalog on X flagged a hidden "Additional sandbox options" in Gemini Desktop
Security watcher TestingCatalog posted screenshots on X showing a new, concealed setting inside Google’s Gemini Desktop app labeled "Additional sandbox options." The feature is not live and Google has not confirmed it, the screenshots indicate. According to the discovery, enabling the setting would expand Gemini’s ability to operate on a macOS device beyond the current chat-window model.
What full access could let Gemini do on macOS
The hidden interface and accompanying copy in the Gemini Desktop app suggest the capability would allow Google's AI to read, create, modify, or delete files "anywhere on your PC," including files outside folders a user has explicitly connected to Gemini. The same internal pop-up says Gemini could communicate with apps such as Mail, Safari, or Messages and perform actions through them. The discovery also indicates the agent could open apps, browse the web, and perform actions without asking for permission every time, depending on which options a user enables.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSafeguards Google says it will keep
Despite the breadth of access described in the hidden options, the screenshots and text emphasize limits on particularly sensitive operations. Gemini would, according to the interface, still ask for confirmation before buying products or transferring money, creating an online account, accepting legal terms on your behalf, or modifying sensitive information about you. The post also notes users can expect "a Claude-like experience, where you explicitly give it permission to use your PC," indicating an expectation of user consent controls for many actions.
Apple is considering making it harder for AI agents to access personal files and data
The way the feature would play out on Apple platforms remains unclear because, the reporting notes, Apple is considering measures to make it difficult for AI agents to access personal files and data on the Mac. That consideration — described alongside TestingCatalog’s discovery — frames the potential for friction between Google’s planned desktop capabilities for Gemini and platform-level restrictions Apple might impose.
What this means for technologists, end users, and policymakers
- Technologists and security teams: Will have a new surface to evaluate if the "Additional sandbox options" arrive — specifically how Gemini accesses files outside connected folders and how app-level interactions (Mail, Safari, Messages) are authorized and audited.
- End users and enterprises: Face decisions about whether to enable broader agent permissions. The hidden interface language warns Gemini may "take actions without asking for your permission first" depending on settings, while also promising prompts for certain sensitive actions.
- Policymakers and platform owners: Apple’s reported consideration of stronger restrictions on AI agents' access to personal data on macOS could shape whether and how Google can deploy Full Access on Apple hardware.
The discovery in TestingCatalog’s screenshots sketches a feature set that would move Gemini from a confined chat window to an agent capable of long-running, cross-application work on a Mac. But the feature is not live, Google has not confirmed it, and key operational details remain unspecified, including when Google might roll out "Full Access" or which Gemini model would power it. The screenshots and in-app text leave a clear imprint: users could enable broad capabilities that let Gemini act across files, apps, and the web — and those choices may depend as much on platform policy as on Google's product decisions.




