Back to Intelligence

Google Gemini Agentic Access on macOS: Defending TCC, File System, and App Control Permissions Before You Regret Granting Them

SA
Security Arsenal Team
October 3, 2026
9 min read

Google is preparing to expand Gemini's capabilities on macOS dramatically. According to reporting from BleepingComputer, the Gemini macOS app could soon gain the ability to access any file on a user's Mac, open and control applications, browse the web, and execute actions autonomously — without prompting the user for permission each time.

This is not a vulnerability disclosure. There is no CVE here. But make no mistake: from a defender's perspective, this is one of the most consequential endpoint security shifts of 2026. An agentic AI process holding Full Disk Access, Accessibility permissions, and Automation entitlements on macOS represents a legitimate, signed, user-consented attack surface that inherits every abuse technique we've spent years hunting in post-exploitation tradecraft — AppleScript-based app control, TCC-protected directory access, browser session interaction — now wrapped in a trusted first-party binary.

If Gemini — or any agentic assistant — is compromised via prompt injection through web content it browses, a malicious document it reads, or a poisoned email it processes, the attacker inherits the agent's permission set. That is the concern every CISO and SOC lead should be modeling right now, before these features ship to managed fleets.

Technical Analysis

What Is Changing

The Gemini macOS application is evolving from a chat interface into an agentic assistant. Based on the reported capabilities, the app will require some combination of the following macOS Transparency, Consent, and Control (TCC) permissions:

  • Full Disk Access (FDA) — read access to the entire user file system, including ~/Library/Mail, Messages databases, Safari data, and TCC-protected folders (Documents, Desktop, Downloads)
  • Accessibility (AX) — the ability to observe and synthesize UI events, effectively controlling other applications
  • Automation / AppleEvents — permission to send AppleEvents to other apps (Finder, Safari, Mail, Terminal), the same mechanism abused by macOS malware families for years
  • Screen Recording (potential) — for visual context of the user's workspace
  • Network access — outbound browsing and API communication with Google services

Why This Matters to Defenders

Three converging risks define the threat model:

1. Agent hijacking via indirect prompt injection. An agent that browses the web and reads files will ingest attacker-controlled content. Indirect prompt injection — instructions hidden in web pages, documents, or emails that the agent processes — can steer the agent into exfiltrating files, sending messages, or executing actions using its granted permissions. The agent's TCC grants become the attacker's TCC grants. No exploit required; the OS sees a consenting, entitled process.

2. TCC permission concentration. macOS security architecture assumes permissions are granted to applications with narrow purposes. Concentrating FDA + Accessibility + Automation in a single always-on process creates a high-value target. Historically, attackers have abused AppleScript and Automation entitlements (MITRE ATT&CK T1059.002, T1548) precisely because they ride on trusted user consent.

3. Enterprise governance gap. Most organizations have no MDM policy controlling which applications receive FDA or Accessibility consent. TCC grants made via user click-through (kTCCServiceSystemPolicyAllFiles, kTCCServiceAccessibility) are invisible to most SIEM pipelines. When Gemini prompts for these permissions, users will click Allow.

Exploitation Status

There is no active exploitation of Gemini itself — this capability has not fully shipped. The relevant exploitation reality is the technique landscape: prompt injection against AI agents is a demonstrated, actively researched attack class with public PoCs throughout 2025, and macOS post-exploitation via AppleEvents/Automation is a mature, in-the-wild technique used by macOS stealers and RATs. Defenders should treat agentic AI permissions as a pre-emptive hardening target, not a wait-and-see item.

Detection & Response

The detections below focus on observable behaviors: the Gemini process receiving sensitive TCC grants, spawning child processes or shell interpreters (anomalous for a chat assistant), and the broader pattern of scripting interpreters driving app control — the tradecraft an attacker would inherit through agent hijacking.

YAML
---
title: Gemini macOS Process Spawning Shell or Script Interpreter
id: 3f8a2b91-6c4d-4e7a-b2f1-9d0e5c8a1b34
status: experimental
description: Detects the Google Gemini macOS application spawning shell interpreters, AppleScript, or automation utilities, which may indicate agent hijacking via prompt injection or abuse of the agent's automation entitlements.
references:
  - https://www.bleepingcomputer.com/news/google/google-gemini-could-soon-get-full-access-to-your-macs-files-apps-and-the-web/
  - https://attack.mitre.org/techniques/T1059/002/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.execution
  - attack.t1059.002
  - attack.t1059.004
logsource:
  category: process_creation
  product: macos
detection:
  selection_parent:
    ParentImage|contains:
      - '/Gemini.app/'
      - 'com.google.Gemini'
  selection_child:
    Image|endswith:
      - '/osascript'
      - '/bash'
      - '/zsh'
      - '/sh'
      - '/python3'
      - '/curl'
      - '/sqlite3'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate agent actions initiated by the user — tune against your approved Gemini use cases
level: high
---
title: AppleScript Automation Targeting Sensitive macOS Applications
id: 8c1d4e72-2a5b-4f69-9c83-7e2b1a4d6f90
status: experimental
description: Detects osascript or AppleEvents automation targeting Mail, Safari, Finder, or Terminal — tradecraft common to macOS post-exploitation and abusable through any process holding Automation entitlements, including agentic AI assistants.
references:
  - https://attack.mitre.org/techniques/T1059/002/
  - https://attack.mitre.org/techniques/T1552/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.execution
  - attack.t1059.002
  - attack.credential_access
detection:
  selection_img:
    Image|endswith: '/osascript'
  selection_cmd:
    CommandLine|contains:
      - 'tell application "Mail"'
      - 'tell application "Safari"'
      - 'tell application "Finder"'
      - 'tell application "Terminal"'
      - 'do shell script'
  condition: selection_img and selection_cmd
falsepositives:
  - Legitimate user or MDM automation workflows; inventory approved AppleScript usage before deployment
level: medium

For Microsoft Defender for Endpoint on macOS and Sentinel, hunt for the Gemini process lineage and any scripting or file-access anomalies beneath it:

KQL — Microsoft Sentinel / Defender
// Hunt: Gemini agent process spawning interpreters or accessing sensitive stores
// Requires Defender for Endpoint on macOS onboarded to Sentinel
let SensitivePaths = dynamic(["/Library/Mail/", "Library/Messages/", "Library/Safari/", "Library/Cookies/", ".ssh/", "Library/Keychains/"]);
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where InitiatingProcessFolderPath has "Gemini" or InitiatingProcessCommandLine has "com.google.Gemini"
| where FileName in~ ("osascript", "bash", "zsh", "sh", "python3", "curl", "wget", "sqlite3")
   or ProcessCommandLine has_any (SensitivePaths)
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessFolderPath,
          FileName, ProcessCommandLine, SHA256, ReportId
| order by TimeGenerated desc;
// Complementary hunt: any process reading TCC.db to enumerate granted permissions (recon of FDA grants)
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where ProcessCommandLine has "TCC.db"
| where FileName !in~ ("mdworker", "tccd")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFolderPath
| order by TimeGenerated desc

For endpoint forensics with Velociraptor, audit TCC grants and Gemini process activity across the fleet. Note that reading TCC.db requires Full Disk Access on the Velociraptor service itself:

VQL — Velociraptor
-- Artifact: macOS Agentic AI Permission Audit
-- Enumerates TCC grants for Full Disk Access, Accessibility, and Automation,
-- and identifies running agentic AI processes (Gemini and peers).

SELECT Name, Pid, Exe, CommandLine, Username
FROM pslist()
WHERE Exe =~ '(?i)gemini|chatgpt|claude|copilot'
   OR CommandLine =~ '(?i)com\.google\.Gemini'
VQL — Velociraptor
-- Artifact: TCC Grant Review for High-Risk Services
-- Requires FDA on the collection context. Reviews per-user TCC databases
-- for Full Disk Access and Accessibility grants to non-system clients.

SELECT client AS Client,
       service AS TCCService,
       auth_value AS AuthValue,
       last_modified AS LastModified
FROM sqlite(file=UserTCCPath,
            query='SELECT client, service, auth_value, last_modified FROM access WHERE service IN ("kTCCServiceSystemPolicyAllFiles", "kTCCServiceAccessibility", "kTCCServiceAppleEvents", "kTCCServiceScreenCapture")')
WHERE Client =~ '(?i)gemini|google'

Verification and Hardening Script (macOS / Bash)

Run locally or via your MDM's script payload to audit current grants and establish a baseline:

Bash / Shell
#!/bin/bash
# Gemini / Agentic AI TCC Audit for macOS endpoints
# Run with sudo for full visibility into user TCC databases.

echo "=== Installed agentic AI applications ==="
mdfind "kMDItemKind == 'Application'" 2>/dev/null | grep -iE 'gemini|chatgpt|claude|copilot' || echo "None found via Spotlight"
ls -d /Applications/* 2>/dev/null | grep -iE 'gemini|chatgpt|claude|copilot'

echo ""
echo "=== Full Disk Access & Accessibility grants (system TCC.db) ==="
sudo sqlite3 /Library/Application\ Support/com.apple.TCC/TCC.db \
  "SELECT client, service, auth_value, datetime(last_modified,'unixepoch') FROM access \
   WHERE service IN ('kTCCServiceSystemPolicyAllFiles','kTCCServiceAccessibility','kTCCServiceScreenCapture');" 2>/dev/null

echo ""
echo "=== Per-user TCC grants (current user) ==="
sqlite3 ~/Library/Application\ Support/com.apple.TCC/TCC.db \
  "SELECT client, service, auth_value, datetime(last_modified,'unixepoch') FROM access \
   WHERE service IN ('kTCCServiceSystemPolicyAllFiles','kTCCServiceAccessibility','kTCCServiceAppleEvents');" 2>/dev/null

echo ""
echo "=== Gemini-specific entitlements and running state ==="
if [ -d "/Applications/Gemini.app" ]; then
  codesign -d --entitlements - "/Applications/Gemini.app" 2>/dev/null
  pgrep -fl "Gemini" || echo "Gemini not currently running"
fi

echo ""
echo "=== Recent osascript executions from unified log (last 24h) ==="
log show --last 24h --predicate 'process == "osascript"' --style compact 2>/dev/null | grep -iE 'Gemini|tell application' | head -50

Remediation

Because this is an emerging product capability rather than a patched vulnerability, remediation is governance and configuration work. Prioritize the following:

  1. Establish an agentic AI policy before users grant consent. Define which AI assistants are approved for corporate macOS endpoints and the maximum permission set each may hold. If Gemini is not approved, block installation via MDM ( Jamf, Kandji, Intune) using application restrictions or Santa/osquery-based binary rules.

  2. Deny Full Disk Access and Accessibility via MDM PPPC profiles. Deploy a Privacy Preferences Policy Control (PPPC) configuration profile that explicitly sets kTCCServiceSystemPolicyAllFiles, kTCCServiceAccessibility, kTCCServiceAppleEvents, and kTCCServiceScreenCapture to Deny for Gemini's bundle identifier. MDM-managed denies override user click-through consent — this is your strongest control. Test profile behavior on macOS Sonoma/Sequoia and later, as Apple periodically changes PPPC enforcement semantics.

  3. Monitor TCC state drift. Baseline the output of the audit script above across your fleet and alert on new FDA/Accessibility grants to any non-MDM-approved client. TCC grants are the persistence mechanism for agentic abuse; treat changes as notable security events.

  4. Deploy the detections above. Onboard macOS endpoints into your EDR (Defender for Endpoint, CrowdStrike, Jamf Protect) and ensure process creation with command-line capture is flowing to your SIEM. The Sigma and KQL content in this post gives you same-day coverage for the highest-risk behaviors.

  5. Train users on indirect prompt injection. When Gemini ships browsing and file access, users must understand that content the agent reads can instruct the agent to act. Establish rules of engagement: agents do not process untrusted email attachments, do not act on instructions found inside documents or web pages, and never transmit files externally without explicit user confirmation.

  6. Watch Google's final implementation. The permission model Gemini ultimately ships — granular vs. all-or-nothing consent, per-action prompts vs. blanket authorization — will determine your residual risk. Review the app's entitlements (codesign -d --entitlements) on day one of any deployment and re-audit TCC grants after every major version update.

The organizations that get ahead of agentic AI permissions now — before these capabilities land on thousands of managed Macs — will avoid the far more painful incident response work later. Treat every AI agent with OS-level permissions as you would a privileged user account: least privilege, monitored, and governed.

Related Resources

Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.