Google's AI bug hunter logs 500+ flaws, only 2 in secure-by-design apps

Source Cryptopolitan

Google’s own AI agent PageBreak has validated over 500 cross-site scripting vulnerabilities in Google’s homegrown web apps. It found only two in hundreds of apps built on the company’s high-assurance web frameworks.

PageBreak flags a bug only after a working exploit runs against a live copy of the target, Google said.

Debug endpoints held both flaws counted

Both hardened-stack bugs were counted as of September 4, 2026. Both were in internal apps or debug endpoints that were not fully hardened.

Google cites the gap, more than 500 findings across its broader set of first-party apps compared with two on the hardened stack, as evidence that safe-by-design frameworks can withstand a relentless automated attacker.

On September 24, Google’s Product Security team announced PageBreak in a blog post by information security engineer Michał Bentkowski. The agent ran as a pilot starting in November 2025, and became a full project in January 2026.

Cross-site scripting, or XSS, is when an attacker injects a script into a page that another user loads. Depending on the app, the script could read data or commandeer a victim’s logged-in session.

Gemini 3.1 Pro scans, and a validator must fire the exploit

Most of the scans are done on Gemini 3.1 Pro and Gemini 3.5 Flash, but PageBreak can also use other models. The second step is what sets it apart from a normal LLM scanner.

Each suspected flaw is passed by the agent to a purpose-built validator. The validator then fires the actual payload against a running instance of the app.

As for XSS, the validator injects a JavaScript payload, loads the page, and ascertains whether the script executes.

Google is pitching PageBreak as a cure for the “AI slop” drowning security teams. Bentkowski’s post talks about LLMs as static code analyzers overwhelming teams with unverified hypotheses, where the hard part was sifting a real, exploitable bug from a plausible hallucination.

In addition to XSS, the validators test for database query injection, path traversal leaks and code execution.

Google runs the same seed over multiple iterations, so an agent who strays down a dead end still gets repeated chances at the right exploit.

Google says unverified candidates never make it to product teams as confirmed bugs. And they continue to feed into later scans or point engineers building the next validator, still within the security workflow.

Google says PageBreak’s false-positive rate is near zero.

The agent’s reach is magnified by Google’s own scale, which an outside researcher can’t replicate. One code repository enables it to trace execution paths across services, and live-traffic security data maps a page request back to the source code.

Existing scanners hand PageBreak logged-in entry to internal sites otherwise hard to reach.

Google plans to integrate PageBreak more tightly with CodeMender, a fix-writing agent, so that teams can review a proposed patch next to a confirmed bug.

Google cited CodeMender in May when its Threat Intelligence Group said it had caught what it believed was the first zero-day exploit created with AI assistance.

Bitcoin Red Team’s August sweep of 501 open source projects generated 7,958 findings over 108 hours, but only 24.7% had reproducible proofs at the time.

Autonomous agents already cross boundaries they weren’t meant to, as Cryptopolitan reported when Gemini reached three real companies during May testing.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
OpenAI tilts toward 2027 IPO as Anthropic prepares to list firstOpenAI is leaning toward postponing its initial public offering until 2027, per a New York Times report on June 25 citing people involved in the company’s internal deliberations. The shift represents a reversal from the late-2026 timeline OpenAI has signaled since January, with CEO Sam Altman rejecting any valuation below $1 trillion and CFO Sarah...
Author  Cryptopolitan
Jun 26, Fri
OpenAI is leaning toward postponing its initial public offering until 2027, per a New York Times report on June 25 citing people involved in the company’s internal deliberations. The shift represents a reversal from the late-2026 timeline OpenAI has signaled since January, with CEO Sam Altman rejecting any valuation below $1 trillion and CFO Sarah...
placeholder
Gold ETFs Just Had Their Second-Biggest Month Ever With $18 Billion InflowGlobal gold exchange-traded funds (ETFs) pulled in $18 billion in August, the second-largest monthly inflow on record, lifting collective holdings to an all-time high of 4,189 tonnes.The World Gold Co
Author  Beincrypto
Sept 11, Fri
Global gold exchange-traded funds (ETFs) pulled in $18 billion in August, the second-largest monthly inflow on record, lifting collective holdings to an all-time high of 4,189 tonnes.The World Gold Co
placeholder
USD/JPY Forecast: Yen Strength Puts 152 Support in Focus as BoJ Tightening LoomsUSD/JPY remains under pressure as the Japanese yen strengthens ahead of another potentially important Bank of Japan policy decision. The pair has fallen toward the mid-155 region after breaking below
Author  Beincrypto
Sept 22, Tue
USD/JPY remains under pressure as the Japanese yen strengthens ahead of another potentially important Bank of Japan policy decision. The pair has fallen toward the mid-155 region after breaking below
placeholder
3 Meme Coins to Watch in the Fourth Week of September 2026Dogwifhat (WIF), Pepe (PEPE), and Dogecoin (DOGE) top the meme coins to watch this week. Each broke out of a multi-month bullish chart pattern on Monday, with volume well above its 20-day average.The
Author  Beincrypto
Sept 23, Wed
Dogwifhat (WIF), Pepe (PEPE), and Dogecoin (DOGE) top the meme coins to watch this week. Each broke out of a multi-month bullish chart pattern on Monday, with volume well above its 20-day average.The
placeholder
Cardano Unlocks AI Agent Payments With x402: ADA Hits 4-Month HighCardano officially joined the x402 payment standard on September 21, letting applications and autonomous AI agents pay for online services directly in ADA.ADA’s price responded immediately, climbing r
Author  Beincrypto
Sept 23, Wed
Cardano officially joined the x402 payment standard on September 21, letting applications and autonomous AI agents pay for online services directly in ADA.ADA’s price responded immediately, climbing r
goTop
quote