# Google's PageBreak AI Agent Finds 500+ Verified XSS Flaws and Builds Working Exploit Chains

> Google's Product Security team disclosed PageBreak, an internal Gemini-based security agent that found over 500 verified cross-site scripting (XSS) vulnerabilities in Google first-party web applications by confirming each suspected flaw with a working exploit against a live environment. It also assembled working exploit chains: cache poisoning on apis.google.com, an XSS in the admin.google.com console, and arbitrary JavaScript execution via the Tag Assistant Extension. No in-the-wild exploitation is reported.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2926
- **ID:** TL-2026-2926
- **Severity:** MEDIUM
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)

## Description

PageBreak is an internal AI agent built by Google's Product Security team to test Google's first-party web applications. It began as a pilot in November 2025 and became a full project in January 2026. Google disclosed it publicly on 2026-09-24 (blog post 'Agentic hacks, real proofs: inside Google's PageBreak project' on blog.google, attributed in press coverage to Michał Bentkowski, plus a Bug Hunters post, 'Google's PageBreak Project', covering real-world findings). Most scans use Gemini models, including Gemini 3.1 Pro and Gemini 3.5 Flash, though the agent can work with other models.

The design priority is deterministic validation. The agent forms hypotheses from code and traffic, then hands each one to a separate, human-written, non-AI validator that tries to exploit it in a live running copy of the application. The XSS validator injects a specific JavaScript payload and uses a rendering harness to check whether the script actually executes. Validators also exist for SQL injection (output and timing changes), path traversal (planted readable files), remote code execution (sleep delays, file writes, DNS/HTTP callbacks) and SSRF (requests reaching internal services). Unverified findings are not sent to product teams as confirmed bugs; they feed later scans and validator development. Google credits its mono-repo, its Security Signals data that maps live HTTP paths to source code, and an existing scanner with credentials to nearly all Google applications. The result is over 500 verified XSS vulnerabilities and a near-zero false-positive rate. Google did not name most affected applications or give a severity breakdown.

Three exploit chains were described. (1) Cache poisoning on apis.google.com: an unchecked URL path segment was reflected into a returned JavaScript file but excluded from the cache key, so a poisoned response could be served to other visitors in the same region, including external sites loading that script. (2) Admin console XSS on admin.google.com: the /a/autodns/registrar endpoint assigned an unverified redirect_uri value to window.location, which a cryptographic signature check initially protected. PageBreak found a separate endpoint, /a/autodns/authorize, that would compute a valid signature for a malicious javascript: URI, which defeated the protection. (3) Tag Assistant Extension universal XSS: weak validation of external connections, recovery of a one-time nonce and unsafe message forwarding let attacker-controlled script content reach the page being debugged, and support for data: URLs allowed arbitrary JavaScript execution.

Applications built on Google's high-assurance (secure-by-design) web frameworks showed only 2 XSS issues across hundreds of applications as of 2026-09-04, both in internal apps or debug endpoints. Google plans to pair PageBreak with CodeMender, its automated fix-generation agent, so that product teams validate proposed patches instead of triaging report accuracy. No CVEs, CVSS scores, attacker infrastructure or exploitation in the wild are reported. The defensive relevance is that AI-driven, proof-validated vulnerability discovery and exploit chaining is now operational at scale, which shortens the window between a flaw's introduction and its discovery by any party using similar tooling.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1659 Content Injection
- T1059.007 JavaScript
- T1176 Software Extensions
- T1539 Steal Web Session Cookie
- T1185 Browser Session Hijacking

## Sources

- [Agentic hacks, real proofs: inside Google's PageBreak project](https://blog.google/security/agentic-hacks-real-proofs-inside-googles-pagebreak-project/)
- [Google's PageBreak Project (Google Bug Hunters)](https://bughunters.google.com/blog/pagebreak-real-world-findings)
- [Google's AI Hacker Finds 500+ XSS Flaws and Builds Working Exploit Chains (Cyber Security News)](https://cybersecuritynews.com/googles-ai-hacker/)
- [Google Built an AI That Hunts Its Own Security Bugs (Decrypt)](https://decrypt.co/379364/google-built-ai-hunts-security-bugs)
- [Google PageBreak Finds More Than 500 XSS Flaws Across Web Apps (Blockonomi)](https://blockonomi.com/google-pagebreak-finds-more-than-500-xss-flaws-across-web-apps/)
- [Google PageBreak AI Agent Finds 500+ XSS Flaws (Cyber Kendra)](https://www.cyberkendra.com/2026/09/google-pagebreak-ai-agent-500-xss-flaws.html)
- [Google PageBreak AI Agent Finds Over 500 XSS Vulnerabilities Across Its Web Applications (GBHackers)](https://gbhackers.com/google-pagebreak-ai-agent/)
- [Google's PageBreak AI Agent Finds More Than 500 Verified XSS Vulnerabilities (Mallory)](https://mallory.ai/stories/01a10b59-72f1-7781-9d22-2326bc62e628)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2926
