Google Gemini AI to gain full computer access: What it means for users
Key Takeaways Google’s Gemini desktop application for macOS may soon gain a “Full Access” permission, significantly expanding its capabilities beyond a conversational AI. This...
Key Takeaways
- Google’s Gemini desktop application for macOS may soon gain a “Full Access” permission, significantly expanding its capabilities beyond a conversational AI.
- This permission could allow Gemini to read, modify, create, and delete files across a Mac, interact with other applications like Mail and Safari, and send/receive network data without repeated user approval.
- While enhancing productivity, this feature introduces substantial cybersecurity and privacy risks, making Gemini a high-value target for various attack vectors, including prompt injection and compromised web pages.
- Google reportedly plans to implement additional confirmation steps for high-risk actions, suggesting a tiered permission model.
Gemini Desktop App Poised for Expanded macOS Control
Google’s Gemini desktop application for macOS is reportedly on the cusp of introducing a “Full Access” permission, a significant enhancement that would grant the AI assistant extensive control over a user’s computer. This capability, discovered within a hidden “Additional sandbox options” setting in a recent Gemini app version, would allow the AI to interact with files, manage applications, and utilize network services directly from the user’s Mac.
Table Of Content
This potential expansion moves Gemini far beyond its current role as a conversational AI, enabling it to perform actions typically reserved for fully trusted desktop applications. The discovered permission text indicates that with these additional sandbox options enabled, Gemini could gain the ability to read, create, modify, or delete files across the entire macOS system.
Notably, Apple itself is reportedly enhancing its controls for Full Disk Access in macOS, acknowledging the increasing power of AI agents and the potential exposure of sensitive user data that such broad permissions entail.
Unprecedented Access and Interaction
The “Full Access” permission could allow Gemini to interact with files located outside of folders explicitly linked to the AI, including data belonging to other users on the same device. Furthermore, the setting might enable the application to communicate with and operate through other installed programs such as Mail, Safari, and Messages.
Beyond local system interaction, the proposed permission model could also empower Gemini to transmit and receive data over a network without requiring individual approval for each connection. This functionality would enable the AI agent to access websites, APIs, cloud services, and user accounts where the user is already authenticated. Such capabilities could significantly boost Gemini’s utility for complex, multi-step tasks, ranging from research and document organization to drafting emails, automating web-based workflows, and interfacing with enterprise tools.
Significant Cybersecurity and Privacy Implications
While promising enhanced productivity, the introduction of “Full Access” raises substantial cybersecurity and privacy concerns. An AI agent with unrestricted access to a user’s files, browser sessions, network services, and communication applications would become an exceptionally attractive target for malicious actors.
Potential attack vectors include prompt injection, exploitation via malicious web pages, compromised browser sessions, or unsafe instructions, all of which could manipulate an agent with such broad permissions. For instance, if a user instructs Gemini to summarize documents from a specific folder while the AI also has web browsing and inter-application communication capabilities, a malicious website could potentially trick the agent into exfiltrating sensitive files, accessing authenticated services, or transmitting data externally.
The risks extend beyond just malicious AI prompts to encompass compromised websites, untrusted documents, deceptive emails, and vulnerabilities in third-party applications. Google is reportedly planning to maintain additional confirmation requirements for particularly sensitive actions. This suggests that Gemini would still seek explicit user approval for activities such as purchasing products, creating accounts, agreeing to legal terms, or altering sensitive personal information, indicating a potential tiered permission structure to differentiate between routine computer-use actions and higher-risk decisions.
The full-access option remains hidden from public view, and Google has not yet made an official announcement. TestingCatalog suggested that these computer-use capabilities might be linked to a future Gemini 4-powered experience, though this speculation is unconfirmed.
What You Should Do
- Exercise Extreme Caution: When this feature becomes available, carefully evaluate the necessity of granting “Full Access” to Gemini.
- Implement Least Privilege: Only enable the most restrictive permissions necessary for Gemini to perform its intended functions. Avoid broad, default “Full Access” if possible.
- Restrict Access to Sensitive Data: Ensure that Gemini’s access is limited to specific, non-sensitive folders and applications. Do not connect it to directories containing highly confidential information.
- Monitor AI Activity: Be vigilant for unusual or unexpected actions performed by Gemini, as this could indicate compromise or misuse.
- Keep Systems Updated: Ensure your macOS and Gemini application are always updated to the latest versions to benefit from security patches.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.