AI
Published 2026-09-24
Verified 2026-10-05

Google PageBreak (24 Sep): internal Gemini-based security agent found and verified 500+ XSS flaws in Google web apps — only 2 in apps on its high-assurance frameworks

Google's Product Security team described PageBreak on 24 September 2026, an internal AI agent that tests Google's own web applications. It started as a pilot in November 2025 and became a full project in January 2026, and mostly runs on Gemini models such as Gemini 3.1 Pro and Gemini 3.5 Flash. Instead of only reporting suspected bugs from code patterns, PageBreak hands each hypothesis to a non-AI validator that fires a real payload at a running application, which Google says gives a near-zero false-positive rate; unverified findings are kept back rather than sent to product teams. Run at scale, it has found more than 500 cross-site scripting (XSS) vulnerabilities across Google first-party web apps, including on sensitive domains. As of 4 September 2026 it had found only two XSS bugs across hundreds of apps built on Google's high-assurance web frameworks, both in internal apps or debug endpoints with hardening gaps. A companion Bug Hunters post details chained finds; secondary reporting cites cache poisoning on apis.google.com, a signature bypass on an admin.google.com endpoint and a universal XSS in the Tag Assistant extension. Google plans to tie PageBreak to its CodeMender fix-generation agent. Google did not break down the findings by product or severity, and there is no sign any were exploited. Wire: Cybersecurity News 5 Oct.

Product
Google PageBreak (internal agentic vulnerability scanner; Gemini models + deterministic validators)
Versions
n/a — internal tool, findings fixed by Google; no CVEs listed
Exploited in Australia?
unknown
Patch to
No action for Google customers. Security teams adopting AI scanners: insist on proof against a running system before a finding reaches developers, and prefer frameworks with auto-escaping, strict CSP and Trusted Types, which Google's results suggest remove most XSS by design.

Primary: Google — Agentic hacks, real proofs: inside Google's PageBreak project (24 Sep 2026) · Vendor: Google Bug Hunters blog (companion PageBreak vulnerability deep dive) · Cybersecurity News — Google's AI hacker finds 500+ XSS flaws and builds working exploit chains (5 Oct 2026)

ai cloud