I haven't tested Apple's access model, but is there something that's stopping Gemini from launching `ghostty -e /bin/sh malware.sh`?
Windows' Vista-era UAC protections have been bypassed through lolbins since the day of its inception (although officially UAC is not a security boundary according to MS) and apps like Ghostty might punch a hole through disk access controls in the same manner.