Google has revealed an internal AI security agent that found more than 500 verified cross-site scripting, or XSS, flaws across its own web applications.
The system, called PageBreak, searches for weaknesses that could let an attacker run unwanted code in a visitor’s browser, including on sensitive services. The announcement matters because AI scanners can generate large numbers of doubtful reports.
PageBreak instead tests each suspected weakness against a live environment, looking for proof that a real attack works before it is sent to engineers. This reduces noise while exposing hidden web weaknesses.
Analysts at tl;dr sec, referenced as Tdr SEC, highlighted PageBreak in their October 1 roundup. This was defensive testing, not malware or a confirmed intrusion. The Big Sleep vulnerability discovery project instead focused on a database flaw.
Google said in a public report, reviewed by Cyber Security News (CSN), that PageBreak began as a pilot in November 2025 and became a full project in January 2026. It primarily uses Gemini models within a proof-driven workflow.
Google’s AI Hacker Finds 500+ XSS Flaws
PageBreak examines code and traffic signals to identify possible weaknesses. It then hands that theory to a purpose-built validator rather than treating the AI output as a final security finding.
For XSS, the validator injects JavaScript, opens the target through a browser-like test system, and checks whether the code actually executes.
Rather than simply flagging risky-looking code, the scanner demonstrates the effect. Google attributes its near-zero false-positive rate to this verification. The same validation method can test SQL injection, path traversal, remote code execution, and server-side request forgery.
The results also tested secure design. As of September 4, 2026, PageBreak found only two XSS issues among hundreds of applications built with its high-assurance web frameworks.
Both were limited to internal applications or debug endpoints with hardening gaps, showing why consistent framework controls can prevent whole classes of bugs.
Exploit Chains Expose Risks
The most notable findings were not simple input errors. In one case, PageBreak found a cache-poisoning issue affecting a JavaScript file server.
An unchecked URL path segment was inserted into returned code but excluded from the cache key, allowing a malicious response to be stored and later delivered to other visitors in the same geographic area.
Google found no evidence that attackers used that cache flaw. Still, it could have led to XSS on sensitive Google domains and external websites that loaded the affected JavaScript.
It reflects risks in CDN cache poisoning attacks, where shared responses can turn an input weakness into browser-side code execution.
A second chain affected the admin console. PageBreak found that an unverified redirect value could reach window.location, but a cryptographic signature initially blocked direct abuse.
The agent discovered a separate authorization endpoint that produced a valid signature for a malicious JavaScript URI, turning a protected endpoint into a working XSS path.
The third case involved the Tag Assistant Extension. Weak checks on external connections, recovery of a one-time nonce, and unsafe message forwarding allowed attacker-controlled script content to reach a page under debugging.
Support for data URLs then enabled arbitrary JavaScript execution, creating a universal XSS condition. Google retains unverified findings for future scans and validator improvements rather than sending them to product teams.
It also acknowledges that incomplete validators can miss genuine weaknesses. Its reported results support combining automated testing with secure frameworks, while engineers still review proposed fixes before changes reach users.
Google is working with automated patching initiatives to address the volume of confirmed reports. The intended outcome is to reduce product teams’ work to validating proposed fixes, rather than repeatedly investigating whether convincing AI-generated reports describe real security problems.
The source contains affected domains and test artifacts, not confirmed malicious infrastructure. These appear below for reference and should not be treated as a blocklist.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.