A teardown by BleepingComputer reveals Google is testing a concealed 'Additional sandbox options' in Gemini for macOS, bypassing scoped bookmarks for ambient file traversal and shell execution. This exposes the OS to catastrophic indirect prompt injection vectors.
For more than four decades, personal computing has been anchored by an unspoken covenant between the operating system, the software application, and the human sitting at the keyboard: no matter how complex
or capable an application became, execution required explicit human intention. Every file open dialogue, every folder authorization prompt, every operating system privilege escalation request served as
a deliberate checkpoint in which human agency was preserved. In Apple's macOS ecosystem, this philosophy reached its zenith through a layered fortress of hardware-enforced protections, including the Transparency,
Consent, and Control (TCC) subsystem, System Integrity Protection (SIP), and mandatory App Sandbox containerization. That paradigm is now facing its most profound structural disruption since the inception
of the graphical user interface. A forensic investigation and codebase deconstruction published by cybersecurity research firm BleepingComputer has revealed that Google is actively testing an experimental,
deeply hidden configuration panel within its native Gemini Desktop application for macOS titled "Additional sandbox options" . If activated, this operational toggle effectively strips away the granular,
scoped constraints that previously restricted the artificial intelligence to designated user folders, granting Gemini comprehensive, autonomous read, write, execution, and deletion permissions across the
user's entire local file hierarchy, system applications, and network sockets. While the immediate promise of this architectural leap is breathtaking enabling an artificial intelligence agent to organize
Read Full Article