Google’s PageBreak AI Agent Finds 500 Flaws in Its Web Apps

Google’s PageBreak AI Agent Unleashes a Torrent of Flaws in Its Web Apps, Highlighting the Power and Pitfalls of AI-Powered Security

In a remarkable display of its own vulnerabilities, Google’s internal AI agent, PageBreak, has identified over 500 cross-site scripting (XSS) flaws in the company’s web applications. This startling discovery serves as a stark reminder that even the most security-conscious organizations can fall prey to the very threats they aim to mitigate. The fact that PageBreak, an AI-powered tool developed by Google’s Product Security team, was able to uncover such a vast number of vulnerabilities highlights both the potential and the pitfalls of relying on artificial intelligence in application security.

PageBreak, which began its pilot phase last November and went live as a full-fledged product in January, uses a combination of AI and deterministic validation to identify vulnerabilities that can be exploited. The tool’s mission is to autonomously scale vulnerability discovery while minimizing manual effort, a goal that aligns with the growing trend of using AI and automation to streamline security processes. By giving large language models (LLMs) access to source code and security tooling, PageBreak enables them to find vulnerabilities faster than human researchers.

However, this approach also raises challenges, such as distinguishing between genuine, exploitable flaws and convincing hallucinations that can increase the burden on product teams rather than reducing it. Google’s information security engineer MichaƂ Bentkowski acknowledged these difficulties in a blog post, where he outlined the company’s vision for using AI to improve application security.

One of the key innovations behind PageBreak is its deterministic approach to exploit validation. By identifying potential weaknesses and attempting to exploit them in a running environment, the tool reports only when the vulnerability can be demonstrated. This near-zero false-positive rate ensures that product teams are not overwhelmed by unverified vulnerability reports, allowing them to focus on addressing genuine threats.

The development of PageBreak highlights the growing importance of AI-powered security tools in identifying and prioritizing vulnerabilities. As Rickard Carlsson, CEO of Detectify, notes, AI security tools have produced more potential vulnerabilities than teams can realistically investigate over the past couple of years. Google’s approach demonstrates a potential direction for defenders to use AI in identifying vulnerabilities without being overwhelmed by false positives.

For organizations looking to leverage AI in their application security efforts, PageBreak serves as a valuable example of what is possible when combining AI with deterministic validation. However, it also underscores the need for caution and careful consideration when relying on AI-powered tools. As Google’s experience demonstrates, even the most advanced AI systems can produce results that require human verification and validation.

Ultimately, PageBreak’s success and limitations serve as a reminder that AI-powered security is not a silver bullet. Rather, it is a powerful tool that must be used judiciously and in conjunction with traditional security practices to ensure effective vulnerability management. By embracing this approach, organizations can harness the potential of AI to improve their application security posture while minimizing the risks associated with relying on these tools alone.

For readers looking to integrate AI-powered security into their own vulnerability management processes, a key takeaway is the importance of verifying and validating results from AI-powered tools. This involves not only using separate, non-AI validators but also implementing rigorous testing and validation procedures to ensure that identified vulnerabilities are genuine threats that require attention. By doing so, organizations can unlock the full potential of AI in application security while minimizing the risks associated with relying on these tools.


Source: Dark Reading — 2026-10-06