Tools & Products

Gemini Desktop Adds Hidden "Full Access" Computer Use Setting: macOS Sandbox Expansion and Security Guardrails

A hidden "Additional sandbox options" panel discovered inside the Gemini Desktop macOS client reveals an upcoming "Full Access" computer use mode. The feature grants the model filesystem-wide read/write permissions, background network dispatch, and inter-app scripting across Safari, Mail, and Messages, powered by Gemini 4.

By FreakVinci · 2026-10-02 · 13 min read

An unreleased configuration screen titled "Additional sandbox options" was uncovered within recent builds of the Gemini Desktop application for macOS. The setting exposes an experimental Full Access operating mode that transitions Gemini from a sandboxed document assistant into an autonomous computer use agent capable of direct OS-level execution.

When enabled, the mode bypasses standard App Sandbox directory boundaries, enabling the agent to execute multistep desktop workflows without requiring individual permission prompts for every file mutation or network request.


Capabilities Under the Full Access Mode

According to the interface disclosure embedded in the application bundle, activating the additional sandbox settings permits Gemini to execute three categories of privileged operations:

+---------------------------------------------------------------------------------+
|                       GEMINI DESKTOP PRIVILEGE SPECIFICATION                     |
+---------------------------------------------------------------------------------+
|                                                                                 |
|  [FILESYSTEM ACCESS]                                                            |
|  - Read, create, modify, or delete files anywhere on the Mac filesystem         |
|  - Access directories outside connected workspace folders                       |
|  - Traverse multi-user volume mounts and local cache stores                     |
|                                                                                 |
|  [NETWORK COMMUNICATIONS]                                                       |
|  - Transmit and receive network data without per-request user approval          |
|  - Connect to external APIs and web services using active session states        |
|  - Dispatch webhook notifications and background download payloads              |
|                                                                                 |
|  [INTER-APPLICATION SCRIPTING]                                                  |
|  - Direct communication with native applications (Safari, Mail, Messages)       |
|  - Execute actions through accessibility and Apple Events script interfaces     |
|  - Read context from active window buffers and dispatch input events            |
|                                                                                 |
+---------------------------------------------------------------------------------+

Enforced Guardrails and Human Confirmation Thresholds

Despite granting broad OS-level autonomy, the client architecture retains hard-coded confirmation barriers that halt execution until a human user clicks an explicit approval modal.

Gemini will not execute the following actions autonomously under any sandbox configuration:

Action Category Trigger Condition Required User Verification
Financial Purchases Checkout buttons, payment gateways, credit card inputs Biometric (Touch ID) or password prompt
Account Creation Sign-up forms, OAuth third-party consent screens Explicit confirmation modal displaying URL and scopes
Legal Agreements Terms of service checkouts, EULA agreements Full text preview with manual acceptance button
Credential Modification Keychain access, SSH keys, passwords, security tokens System security prompt via macOS Authorization Services

+---------------------------------------------------------------------------------+
|                 GEMINI DESKTOP MACOS SANDBOX EXECUTION PIPELINE                 |
+---------------------------------------------------------------------------------+
|                                                                                 |
|   User Prompt ("Audit downloads folder and email summary to team via Mail")     |
|                                     |                                           |
|                                     v                                           |
|                      +-----------------------------+                            |
|                      |   Gemini 4 Reasoning Engine |                            |
|                      |  (Action Sequence Planning) |                            |
|                      +--------------+--------------+                            |
|                                     |                                           |
|                                     v                                           |
|                      +-----------------------------+                            |
|                      |  Action Safety Classifier   |                            |
|                      +--------------+--------------+                            |
|                                     |                                           |
|                  +------------------+------------------+                        |
|                  | Sensitive Action?                   | Non-Sensitive Action?  |
|                  v                                     v                        |
|   +-----------------------------+       +-----------------------------+         |
|   | Human Confirmation Required |       | Full Access Sandbox Gate    |         |
|   | (Payment, Auth, Legal T&C)  |       | (Inspects Setting Toggle)   |         |
|   +--------------+--------------+       +--------------+--------------+         |
|                  | Approved                            | Active                 |
|                  +------------------+------------------+                        |
|                                     |                                           |
|                                     v                                           |
|                      +-----------------------------+                            |
|                      | macOS Execution Bridge      |                            |
|                      | - posix_spawn / fs hooks    |                            |
|                      | - AppleScript / NSAppleEvent|                            |
|                      | - URLSession background     |                            |
|                      +--------------+--------------+                            |
|                                     |                                           |
|                                     v                                           |
|                      +-----------------------------+                            |
|                      | Target Applications & Disk  |                            |
|                      | [Filesystem] [Safari] [Mail]|                            |
|                      +-----------------------------+                            |
+---------------------------------------------------------------------------------+

Technical Architecture: How Gemini Interacts with macOS

Standard macOS applications distributed through official developer channels adhere to Apple's App Sandbox guidelines, which confine read/write operations to application-specific container directories (~/Library/Containers/).

To deliver computer use functionality, the Gemini Desktop client combines three distinct system layers:

  1. Accessibility and Display Server Inspection: Using the macOS Accessibility API (AXUIElement), Gemini captures semantic UI trees across active applications, identifying text labels, interactive buttons, and table rows without relying exclusively on raw pixel classification.
  2. Apple Events and Scripting Bridge: For supported productivity apps such as Mail, Safari, Notes, and Calendar, Gemini dispatches structured Apple Events via the Objective-C / Swift Scripting Bridge. This avoids simulating brittle mouse movements when creating emails, searching tabs, or reading message threads.
  3. Privileged Helper Daemon: To manipulate files outside the standard application sandbox, the app prompts users during initial setup to install a background helper tool registered with SMJobBless or macOS 13+ SMAppService. This daemon operates with user-level privileges, verifying incoming action requests against the active session token before executing filesystem commands.

The Role of Gemini 4

Industry benchmarks indicate that reliable computer use requires frontier reasoning models with high spatial grounding and low error rates on long execution chains. Autonomous desktop agents frequently fail when an unexpected modal dialog appears, an application crashes, or a network request times out.

The Full Access capability in Gemini Desktop is architected to utilize Gemini 4, Google's recently detailed frontier model family. Gemini 4's 2-million-token context window allows the client to maintain complete session history—including terminal logs, accessibility tree snapshots, and previous application states—preventing context loss during multi-hour background tasks.


Enterprise and Security Implications

The introduction of Full Access permissions raises distinct considerations for enterprise IT administrators managing corporate Mac fleets:

  • MDM Restriction Profiles: Mobile Device Management (MDM) platforms such as Jamf, Kandji, and Intune will require configuration payloads to disable the "Additional sandbox options" toggle across managed enterprise hardware.
  • Data Loss Prevention (DLP): Because Gemini can read files across multiple local directories and dispatch data over the network, organizations handling regulated customer data (HIPAA, SOC 2, GDPR) will need audit logging for every local action taken by desktop AI agents.
  • Prompt Injection Risks: If Gemini processes an incoming email or web page containing hidden prompt injection instructions, an unrestricted desktop agent could be coerced into exfiltrating local documents. Google's dual-tier safety classifier is designed to intercept anomalous actions before they reach the execution daemon.