Google PageBreak AI Agent Finds 500+ XSS Flaws

Applications built on Google's own secure-by-design frameworks gave the agent almost nothing: two XSS bugs across hundreds of apps.

By Vivek • • 5 Min Read • 0 • Follow on Google News Add to Preferred Source
Google PageBreak

Google’s Product Security team has disclosed PageBreak, an internal AI agent that has found and verified more than 500 cross-site scripting (XSS) vulnerabilities across Google’s own web applications, including some on sensitive domains. As detailed on blogpot by information security engineer Michał Bentkowski, the agent only reports a bug after a separate, non-AI validator confirms it using a working exploit. Google says this design keeps PageBreak’s false-positive rate close to zero.

PageBreak started as a pilot in November 2025 and became a full project in January 2026. It can run on different models, but Google says most of its usage relies on Gemini, such as Gemini 3.1 Pro and Gemini 3.5 Flash. The agent is internal. Google tests it only against its own first-party applications and has not said it will release it.

Google built PageBreak to cut down on noise. Bentkowski wrote that LLM-based scanners now flood security teams with plausible but unverified bug reports, which he described as “AI slop.” He called the task of distinguishing “a genuine, exploitable flaw from a convincing hallucination” a major challenge that often adds work for product teams rather than removing it.

How PageBreak proves a bug

PageBreak’s agent forms a hypothesis about a flaw. It then hands that hypothesis to a validator written by humans, not the AI. The validator fires a real payload against a running environment. For XSS, a flaw that lets an attacker run their own script in a victim’s browser, the validator injects JavaScript and loads the page in a rendering harness to check whether the code actually executes.

Google’s other validators each check for proof of a different kind of attack:

  • SQL injection: the validator checks whether database queries change their output or their execution time.
  • Path traversal: it plants a file in a world-readable location and tries to read it back through the application.
  • Remote code execution: it looks for sleep delays, file writes, or outbound DNS and HTTP requests.
  • Server-side request forgery: it watches for the application calling an internal service.

Google says the validators can’t cover every type of vulnerability, so PageBreak will miss some real flaws. Findings that the agent can’t verify never reach product teams. Instead, they seed later scans and show where a new validator is needed. The agent can also report what access it would need to confirm a finding. Google runs the agent with identical seeds across many iterations to raise the odds that it finds the working exploit path.

Three bugs Google chose to show

In a companion post on its Bug Hunters blog, Google walked through three of PageBreak’s findings.

Cache poisoning on apis.google.com. The first was a flaw in the routing setup of the static file server that delivers JavaScript on apis.google.com. The server’s cache key left out a path variable, so a malicious request and a request for the real api.js file produced the same key. That lets an attacker replace the cached script with their own code. Google said the poisoned copy would only reach users near the attack’s origin. It also said it found no evidence that anyone exploited the flaw.

Signature bypass on admin.google.com. The second was an XSS flaw on admin.google.com. The vulnerable request needed a valid cryptographic signature, which normally blocks exploitation. PageBreak found on its own that a separate authorization endpoint would sign a malicious javascript: URI using the same key. An attacker could use that signature in the final exploit URL.

Universal XSS in Tag Assistant. The third was a universal XSS flaw in Google’s Tag Assistant browser extension. The extension accepted connections from any google subdomain without checking the exact sender. That meant an XSS bug anywhere on google.com could open a connection to it. From there, an attacker could steal a one-time nonce from the Google Tag Manager debug handshake. The extension would then pass the attacker’s message to the debugged page, allowing them to run JavaScript on any site the user visited.

Applications built on Google’s high-assurance web frameworks gave PageBreak very little to find. Google described those frameworks in 2025 as a way to rule out whole classes of web bugs by default. As of 4 September 2026, the agent had found only two XSS flaws across hundreds of apps built on them, and both were in internal apps or debug endpoints with hardening gaps. So the same company whose broader codebase produced more than 500 verified XSS bugs also owns the codebase where its AI attacker found almost nothing.

Google also acknowledged that PageBreak has advantages most organisations don’t have. It can trace execution paths through Google’s monorepo, which holds billions of lines of code. It can use Security Signals data to map live HTTP paths to specific lines of source code. And it builds on an existing scanner that can log in to nearly every Google web application.

Google has not said which applications held the 500-plus flaws, how severe they were, or how many have been fixed. Google says its next step is to connect PageBreak with CodeMender, its automated bug-fixing agent. The goal is for product teams to do little more than approve proposed fixes. The flaws are in Google’s own services, so regular users don’t need to do anything.

Community Discussion

Join the conversation. Ask questions, share solutions, and help others.

0 Comments

Be the first to start the discussion!

Leave a Comment

Your email address will not be published. Required fields are marked *

We respect your privacy, your information is safe with us.

Latest Articles

View all