Google’s PageBreak AI Agent Finds 500 Flaws in Its Web Apps

Google’s Internal AI Agent Uncovers 500 Vulnerabilities in Web Apps, Raising Questions About AI-Powered Security

A recent revelation from Google has shed light on the company’s internal efforts to bolster its web application security using artificial intelligence (AI). PageBreak, an AI agent developed by Google’s Product Security team, has discovered over 500 cross-site scripting (XSS) flaws in the company’s own web applications. This development highlights a growing trend of utilizing AI and deterministic validation to identify vulnerabilities and assess their exploitability.

The discovery is significant because it showcases how AI can be leveraged to streamline security testing processes and reduce manual effort. PageBreak, which began as a pilot project last November and was later rolled out in January, uses a combination of AI and validation to provide an overview of vulnerabilities that can likely be exploited. This approach enables the agent to autonomously scale vulnerability discovery while minimizing manual toil.

Among the flaws identified by PageBreak are a cache poisoning issue on apis.google.com, an XSS flaw on admin.google.com, and insecure external handshakes in browser extensions. Google has since fixed these issues, but the company remains tight-lipped about the status of fixes for all 500 vulnerabilities discovered by PageBreak. However, it’s worth noting that Google plans to integrate PageBreak with CodeMender, its automated vulnerability-fixing system, which will enable the agent to generate proposed fixes for product engineers to validate and apply.

What’s perhaps more intriguing is PageBreak’s innovative approach to using large language models (LLMs) in application security. By giving these models access to source code and security tooling, Google has enabled them to identify vulnerabilities faster than human researchers. However, this approach also raises challenges, such as distinguishing genuine flaws from convincing hallucinations.

To address this challenge, PageBreak employs a deterministic exploit validation process that establishes which flaws are truly worth addressing. This involves identifying potential weaknesses, attempting to exploit them in a running environment, and reporting results only when the vulnerability can be demonstrated. The agent achieves a near-zero false-positive rate by passing hypotheses to specialized validators that execute real payloads to confirm exploits.

This development has significant implications for security teams looking to leverage AI to help investigate flaws without being overwhelmed by false positives. By using a deterministic approach, Google’s PageBreak is able to streamline the process of vulnerability discovery and validation, ensuring that product teams are not burdened with unverified reports.

As the cybersecurity landscape continues to evolve, it’s clear that AI-powered security tools like PageBreak will play an increasingly crucial role in identifying vulnerabilities and mitigating threats. For defenders, this development serves as a reminder of the potential benefits of using AI to augment traditional security testing methods and improve overall security posture. By embracing innovative approaches like PageBreak, organizations can stay ahead of emerging threats and reduce their exposure to potential exploits.

In practice, this means that security teams should consider integrating AI-powered tools like PageBreak into their vulnerability assessment processes. While there are still challenges associated with using AI in security testing, the benefits of improved accuracy and efficiency cannot be overstated. By leveraging the power of AI, organizations can reduce manual effort, minimize false positives, and focus on addressing critical vulnerabilities that require immediate attention.


Source: Dark Reading — 2026-10-06