www.darkreading.com 6 Oct 2026, 17:56 UTC

Google AI Agent Finds 500 XSS Flaws Across Its Web Apps

GOOGLE has disclosed that its PageBreak AI agent identified more than 500 cross-site scripting (XSS) flaws across its own Web applications. The effort uses a combination of artificial intelligence and deterministic validation to map vulnerabilities to exploitable outcomes and prioritise fixes.

PageBreak, an autonomous testing tool developed by Google’s Product Security team, began piloting in November 2025 and became a full product in January 2026, with the goal of scaling vulnerability discovery while minimising manual toil. The reported flaws include a cache poisoning issue in apis.google[.]com, an XSS flaw in admin.google[.]com, and insecure external handshakes in browser extensions; Google states these three flaws have been fixed and references a companion blog post detailing the real-world findings.

The article explains PageBreak’s approach to patch prioritisation: it first identifies a potential weakness, then attempts to exploit it in a live environment, and only reports a confirmed finding after a successful payload demonstration via a non‑AI validator. This reduces false positives and aims to prevent overwhelming product teams. Google plans to integrate PageBreak with CodeMender, an automated vulnerability‑fixing system, so that verified flaws can be proposed for engineers to validate and deploy.

Experts quoted in the piece emphasise that while AI can uncover vulnerabilities at scale, the decisive factor is reliable, deterministic validation against the running application to verify exploitability before action is taken. The article notes ongoing debates about balancing speed, accuracy, and the burden on engineering teams. Dated 6 October 2026.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline