// 1 CRITICAL · 1 ZERO-DAY · 1 CVE · 1 EXPLOIT IN THE LAST 24H→
An unconfirmed leak reveals a hidden feature in Gemini Desktop for macOS that would expand the AI's permissions beyond user-authorized folders. Google has not commented.

A hidden feature called "Additional sandbox options" was spotted in the Gemini Desktop app for macOS on October 3, 2026. The observation, published by TestingCatalog on X and picked up by BleepingComputer, indicates Google is experimenting with a significant expansion of the AI assistant's permissions: access to files, apps, and the web without asking for confirmation for every action. The feature is not active, and the Mountain View company has released no official comment.

Key Takeaways
  • A hidden "Additional sandbox options" feature has been detected in the Gemini Desktop app for macOS, according to TestingCatalog's observation on X
  • The feature would expand Gemini's access to all system files, beyond the "Connected folders" currently authorized by the user with explicit permission
  • The hidden interface includes safeguards: confirmation required for purchases, money transfers, account creation, and modification of sensitive information
  • Apple is considering measures to make it harder for AI agents to access personal files on Mac, according to the same source

From Authorized Folders to Global Filesystem: The Permission Leap

Gemini Spark on macOS, launched in June 2026, currently operates with a selective authorization model. The user grants explicit permission to specific "Connected folders," a mechanism that requires a Google AI Ultra subscription at $99+ per month. This approach confines the assistant to a user-defined perimeter, with granular control over which documents the AI can read or modify.

The "Additional sandbox options" feature would represent a paradigm inversion. According to the hidden interface text cited by BleepingComputer, enabling the option expands "what Gemini can do and access on your Mac." The same interface specifies that "Gemini may be permitted to take actions without asking for your permission first," depending on the chosen settings. The assistant could therefore read, create, modify, or delete files in any filesystem location, communicate with apps like Mail, Safari, or Messages, and perform actions through them.

"By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac" Google, hidden Gemini Desktop interface, cited by BleepingComputer

Declared Safeguards and Gray Areas

The hidden interface does not abandon human control entirely. The source reports that Gemini would still require confirmation before sensitive actions: purchases, money transfers, account creation, acceptance of legal terms, or modification of sensitive information. This two-speed architecture — general autonomy with emergency brakes for high-impact operations — reflects a central design tension in the desktop AI agent sector.

The dossier does not, however, specify the technical functioning of the expanded sandbox mechanism. No details emerge on how Google intends to isolate the agent from the host system, which macOS APIs it would leverage, or whether the feature will be available to all users or limited to specific subscription tiers. The very nature of the leak — a third-party observation of hidden code — prevents establishing whether this is an internal experiment, a feature in active development, or a test artifact never intended for release.

The Apple Comparison: Two Colliding Philosophies

The same source reporting the leak indicates that Apple is considering measures to make it harder for AI agents to access personal files on Mac. If confirmed, this orientation would outline a stark strategic divergence between the two industry giants. Google appears to be pushing toward a controlled expansion of the agent's boundaries, Apple toward a hardening of barriers.

The contrast sits at a moment of redefinition for the role of AI agents on personal devices. Google's choice — if the leak reflects an actual strategic direction — would position Gemini in a tier of greater operational autonomy compared to competitors, with implications not only for individual privacy but for enterprise security in organizations that deploy Macs with sensitive data.

What to Do Now

For Gemini Spark users on macOS, the immediate signal is to verify the current access perimeter. The $99+ monthly subscription activates "Connected folders," which require explicit folder-by-folder authorization: this model remains the only one available and is unchanged by the leak.

If the "Additional sandbox options" feature ships, three elements will bear monitoring: the granularity of opt-in settings, the list of actions that retain a confirmation requirement, and any changes to the terms of service. At present, none of this information is available.

For IT administrators, the brief provides no operational guidance: the feature is not active, not confirmed, and no documented containment measures exist. The relevant signal remains the direction indicated by the hidden code, not an immediate threat.

Frequently Asked Questions

Is the "Additional sandbox options" feature available now?

No. According to the source, the feature is not active and Google has not confirmed its development. This is an observation of hidden code in the app, not a user-accessible feature.

What is the difference from Gemini Spark's "Connected folders"?

Gemini Spark, launched in June 2026, requires explicit user permission for specific folders. The hidden feature would instead extend access to the entire filesystem without case-by-case authorization, with safeguards only for sensitive actions.

Has the leak been independently verified?

No. The primary source relies on a TestingCatalog observation on X. No official Google source nor other independent sources have confirmed the hidden interface's content at the time of writing.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. gemini.google
  3. blog.google
  4. 9to5google.com
  5. techcrunch.com
  6. support.google.com