Gemini Desktop Tests Hidden "Full Access" Mode: Unrestricted File Access and App Control on macOS
A hidden experimental setting labeled "Additional sandbox options" discovered inside recent Gemini Desktop builds unlocks an unconstrained Full Access mode, allowing Gemini to read, mutate, and delete files across any directory on macOS and orchestrate native apps.
Reverse engineering of recent Google Gemini Desktop builds revealed an unreleased administrative panel labeled "Additional sandbox options."
When enabled via hidden feature flags, the setting introduces an autonomous "Full Access" profile. This grants the local Gemini runtime permission to interact with the entire macOS filesystem, dispatch network traffic without per-socket approval, and orchestrate other running desktop applications.
The discovery indicates Google is preparing to deploy general computer-use agent capabilities, transitioning Gemini from a sandboxed chat client into an operating-system-level agentic worker.
The Leaked Sandbox Settings: What Gemini Requests
The strings discovered inside the desktop binary outline the operational permissions associated with Full Access:
"By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac. Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first, including:
- Reading, creating, modifying, or deleting files anywhere on your Mac, including files outside your connected folders and files belonging to other people stored on your device.
- Sending and receiving data over the network without your approval for each connection, including accessing websites, APIs, and services you are logged into.
- Communicating with other applications on your Mac (such as Mail, Safari, or Messages) and performing actions through them."
Technical Permission Architecture: Sandboxed vs. Full Access
On macOS, sandboxed applications are restricted by Apple's App Sandbox container rules, barring them from touching files outside designated ~/Library/Containers trees unless the user explicitly drags files into the window or grants Full Disk Access in System Settings.
| Permission Dimension | Default Gemini Desktop | Hidden "Full Access" Mode |
|---|---|---|
| Filesystem Reach | Explicitly connected folders only | Complete disk read/write/delete (/) |
| Network Egress | Whitelisted Google endpoints | Arbitrary sockets, cURL, web scraping |
| Application IPC | None | AppleScript, AppleEvents, Accessibility API |
| Prompt Approval | Every file read triggers approval dialog | Zero prompts for routine developer actions |
| Hard Safety Gate | User confirmation required | Still required for checkout, credentials, and legal terms |
Retained Safety Invariants
Despite the expansive permission grant, the code maintains strict client-side gatekeepers to prevent catastrophic autonomy. The software will continue demanding explicit, interactive user consent before executing:
- Financial Checkout Flows: Submitting credit card details or approving digital wallet transactions.
- Account Provisioning: Registering new accounts or changing existing service passwords.
- Legal Terms Acceptance: Signing contracts or checking "I Agree" boxes on behalf of the user.
- Sensitive Profile Mutation: Modifying personal identity records, security keys, or biometric settings.
The Link to Gemini 4 Computer-Use Models
The timing of this interface surfacing aligns with disclosures surrounding Google’s next-generation Gemini 4 model architecture.
While Anthropic previously launched computer use through Claude Sonnet using visual coordinate clicks, Google’s approach combines visual screenshot analysis with direct OS accessibility tree traversal. By communicating directly through system APIs rather than pure pixel clicking, Gemini achieves higher execution speeds and greater resilience against UI theme changes.
Security analysts caution that granting broad read/write capabilities across multi-user Mac workstations introduces prompt-injection attack surfaces. If an agent processes an untrusted email or PDF containing hidden jailbreak instructions, unconstrained disk access could allow malicious scripts to overwrite shell configurations or harvest session tokens. Google appears to be keeping the feature behind internal dogfooding flags while testing automated guardrails.