On October 3, 2026, BleepingComputer reported that researchers at TestingCatalog found a hidden, unreleased setting inside the Google Gemini Desktop app for Mac. It could one day let Gemini read, create, change, or delete your files, work through apps like Mail and Safari, and browse the web for you. It would also ask for permission less often.
If you’re worried, take a breath: Google Gemini doesn’t have broad Mac file access today. The feature hasn’t shipped, and Google hasn’t confirmed it. It’s an early signal, and there’s no switch for you to flip. macOS also has its own permission system that you control, although Google hasn’t said how the feature would work with it. We’ll separate what’s confirmed from what’s only reported, so you don’t change anything on your Mac based on a rumor. (Sources retrieved October 4, 2026.)
What Happened
What researchers actually found
According to BleepingComputer’s October 3, 2026 report, TestingCatalog spotted a setting called Additional sandbox options in the Gemini Desktop app for macOS. It’s hidden, so regular users can’t see it or turn it on.
The interface text reportedly reads: “By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac.” It also warns that Gemini may take some actions without asking first.
A quick word on “sandbox.” On a Mac, a sandbox is a walled-off space that limits what an app can touch. Apple’s developer documentation on the macOS app sandbox explains that sandboxed apps only reach files outside their own space when you grant access. Gemini’s reported setting would loosen those limits for Gemini.
What’s not confirmed: Google hasn’t announced this feature or given a launch date. It also hasn’t said which Gemini model would power it. Everything here comes from text found in a pre-release build, as the report describes it.
What the setting would reportedly do
If it ships as described, the setting would let Gemini:
- Read, create, modify, or delete files anywhere on your Mac, including outside the folders you’ve connected to Gemini
- Work through native Mac apps, including Mail, Safari, and Messages
- Browse the web on your behalf
- Complete multi-step tasks across those apps, instead of staying in a chat window
BleepingComputer frames this as part of Google’s wider “computer-use” plans for Gemini. That’s the industry term for AI that runs a computer the way you do. It clicks, types, and opens apps.
What would still need your explicit approval
The report says Gemini would still stop and ask before higher-risk actions, even with the setting on. Those include:
- Making a purchase
- Transferring money
- Creating an online account
- Agreeing to legal terms
- Changing sensitive personal information
So the reported trade-off is fewer prompts for everyday tasks, with hard stops for anything involving money, contracts, or identity.
Who this affects
On your Mac (macOS)
This report only concerns the Gemini Desktop app for Mac. The app itself is real and available. It needs a Mac with Apple silicon running macOS Sequoia 15 or later, with at least 8 GB of RAM and 200 MB of free storage (Google). The Additional sandbox options setting is not. If you don’t use the Gemini Mac app, nothing in this report touches your computer.
Apple hasn’t changed anything either. macOS works exactly as it did yesterday. Apple’s controls live in System Settings > Privacy & Security, and apps still need your permission to reach protected areas.
On the web (gemini.google.com)
The report doesn’t describe any change to Gemini in a browser at gemini.google.com. A website in Safari or Chrome can’t browse your Mac’s files on its own. It only sees files you choose to upload. A desktop app with granted permissions can. If you use Gemini only on the web, this report doesn’t affect you.
The details
| Item | Status | Source |
|---|---|---|
| Gemini Desktop app for Mac | Available now (Apple silicon, macOS Sequoia 15 or later, 8 GB RAM, 200 MB free storage) | |
| “Additional sandbox options” setting | Hidden, unreleased | BleepingComputer, Oct 3, 2026 |
| Launch date | Not announced | Same |
| Gemini model powering it | Not announced | Same |
| Pricing for this feature | Not announced | TestingCatalog, Oct 2, 2026 |
How It Stacks Up
The fairest comparison is Gemini’s reported setting vs. the permission system your Mac already uses. Here’s how Apple’s documented controls line up.
| Control | What it covers | How access is granted | Source |
|---|---|---|---|
| Files and Folders (macOS) | Desktop, Documents, Downloads, iCloud Drive, network volumes, and removable volumes | The app asks; you approve. Manage it later in System Settings > Privacy & Security > Files and Folders | Apple Support |
| Full Disk Access (macOS) | Nearly all files, including Mail, Messages, Safari history, Time Machine backups, and some admin data | Only you can turn it on in System Settings > Privacy & Security > Full Disk Access. An app can’t grant it to itself | Apple Support, Apple Platform Security |
| Accessibility and Automation (macOS) | Accessibility lets an app control your Mac. Automation lets an app control other apps | Granted per app in Privacy & Security | Apple Support |
| Additional sandbox options (Gemini, reported) | Reading, creating, modifying, or deleting files anywhere on the Mac; native apps (Mail, Safari, Messages); web browsing; multi-step tasks | A toggle inside the Gemini app; fewer prompts for low-risk actions, confirmation for high-risk ones | BleepingComputer |
The open question is how this toggle would interact with macOS. Apple’s documentation says an app needs your approval for protected locations, and only you can grant Full Disk Access. Google hasn’t explained whether the reported setting would rely on Full Disk Access, Accessibility, Automation, or a mix of them. An agent like this might ask for several of those permissions, and each one you grant widens what it can reach. Our reading of Apple’s docs is that you’d see those macOS requests before Gemini gets broad access, but that’s an inference, not a confirmed design. Once they’re granted, the Gemini setting would decide how often Gemini checks in with you.
Apple is also tightening things. On October 2, 2026, Apple posted a developer news update about adding more controls around Full Disk Access. Apple’s post says these extra controls will require very explicit action to grant Full Disk Access, and it warns that the risks of that access grow as AI agents become more capable and autonomous. Apple is moving toward more user control over broad file access, just as AI assistants push for more reach.
What about Android and Windows? There’s no confirmed equivalent to compare against. The sources don’t describe a matching Gemini feature on Google Pixel or Samsung Galaxy phones. They also don’t show a Microsoft Copilot feature on Windows with the same mix of files, native apps, web, and reduced prompts.
On the Mac side, other assistants also ask for macOS permissions. The ChatGPT desktop app, for example, requests Accessibility access for certain features. But there’s no similar “expand what it can access” toggle for ChatGPT. Siri and Apple Intelligence work inside Apple’s existing permission framework.
The Reaction
So far, the reaction comes from the people covering the leak, not from Google, which hasn’t announced the feature. TestingCatalog, which spotted the setting, describes it as a step toward a general computer-use mode for longer workflows across the desktop, rather than access limited to folders you pick. BleepingComputer focuses on the scope instead: the hidden setting’s own text says Gemini may be allowed to act without asking first, including on files outside your connected folders.
Apple’s view of the risk arrived a day before the report. In its October 2 developer update, Apple said some developers misuse Full Disk Access, that users often don’t understand what they’re granting, and that the stakes rise as AI agents become more autonomous. That’s the core worry with any agent that gets wide access: a malicious web page or document can hide instructions that trick an AI into acting against you, a problem known as prompt injection.
Our read: the cautious side has the better argument. “Fewer prompts” sounds convenient until you remember that prompts are the moment you catch a mistake.
Our Take
Verdict: Too early to call Google better or worse. Apple’s existing model is still the stronger safety net, and you don’t need to do anything yet.
Google’s reported guardrail list is sensible. Requiring confirmation for payments, transfers, account creation, legal terms, and sensitive data changes covers the scariest cases. But the core trade-off is real. Fewer prompts means less friction and less oversight. Prompt injection is an unsolved problem for AI agents in general, and broad file access raises the stakes.
Apple’s approach is more cautious. Its docs show a layered system where you grant each type of access yourself. Its October 2 update points to even more control over Full Disk Access. Apple’s AI won’t do more because of this. Your Mac’s defaults just get harder to bypass.
Should you upgrade or change anything? There’s nothing to upgrade to. The setting isn’t available. Keep the Gemini app updated as you normally would. Don’t change any Mac privacy settings because of this report alone. Don’t revoke or grant permissions out of worry or excitement over an unreleased feature.
What to do next
If you’d like peace of mind, take a quick look without changing anything. Go to System Settings > Privacy & Security > Full Disk Access and see which apps are listed. This check is optional, and the unreleased Gemini setting won’t appear there. Knowing what’s listed now makes it easy to spot changes if Gemini ever asks for more.
If you’re the cautious type and plan to try AI agents later, two habits help with any assistant. Keep a current Time Machine backup on an external SSD. And store your passwords in a password manager rather than in files an AI might read.
Wrapping Up
The headline sounds dramatic, but the reality is calmer. Google appears to be building a way for Gemini to work across your Mac with fewer interruptions. It hasn’t confirmed that plan, and today macOS permissions remain your main control over what apps can reach. We’d want Google to explain exactly how this setting works with Apple’s permissions before anyone turns it on.
| Question | Short answer | Applies to |
|---|---|---|
| Is the feature live? | No, it’s hidden and unconfirmed | Gemini Desktop app for Mac |
| What would it do? | Read, create, change, or delete files; work through Mail/Safari/Messages; browse; run tasks | Mac only, per the report |
| What still needs approval? | Purchases, money transfers, new accounts, legal terms, sensitive data changes | Gemini, per the report |
| Android or Windows equivalent? | None confirmed in current evidence | n/a |
| Change Mac settings now? | No, just review what’s listed if you’re curious | macOS Privacy & Security |