Google Gemini Tests Full macOS File, App, and Web Access – Potential AI‑Driven Control Risk
What Happened – Google is testing a hidden “Additional sandbox options” setting in the Gemini Desktop app that, if enabled, would let Gemini read, create, modify, or delete any file on a macOS device, interact with native apps (Mail, Safari, Messages) and browse the web without prompting the user for permission each time. The feature is not yet live and Google has not officially confirmed it.
Why It Matters for Trust & Control Assurance
- This scenario tests the access‑control and AI‑governance control objective: organizations must ensure that privileged actions—whether performed by humans or AI agents—are authorized, logged, and auditable.
- Continuous control‑assurance programs need to capture evidence that any expanded AI permissions are governed by policy, monitored in real time, and can be revoked on demand.
- Verisq’s Control Mapping capability helps map this emerging AI‑access risk to the VCF spine, providing the evidence needed for audit readiness across multiple frameworks (e.g., NIST CSF, ISO 27001).
Who Is Affected – End‑users of macOS devices, enterprise IT departments deploying AI assistants, SaaS providers integrating Gemini, and any organization that permits AI‑driven automation on employee workstations.
Recommended Actions
- Review and tighten your endpoint policy to require explicit, per‑action consent for any third‑party AI integration.
- Enable logging of file‑system and application‑level actions initiated by AI agents; ensure logs are immutable and retained per your audit schedule.
- Conduct a risk assessment against the “AI‑enabled privileged access” control objective and map findings to your framework of record.
Technical Notes – The feature is a hidden UI toggle within Gemini Desktop; it would grant the AI process OS‑level permissions equivalent to a user with full read/write rights. No CVE is associated yet, as the capability is under test, not a disclosed vulnerability. Source: BleepingComputer