{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/google-pagebreak-web-vulnerability-agent-2026/",
 "asOf": "2026-09-26",
 "id": "google-pagebreak-web-vulnerability-agent-2026",
 "date": "2026-09-24",
 "datePrecision": "day",
 "title": "Google's PageBreak agent finds over 500 XSS bugs in its own web apps using deterministic validators",
 "lane": "defense",
 "kind": "tool-release",
 "summary": "Google's Product Security team describes PageBreak, an internal agent mostly using Gemini models that hunts vulnerabilities in Google's first-party web applications and only reports findings confirmed by non-AI validators against running applications. Google reports over 500 XSS vulnerabilities found with near-zero false positives, while apps on its high-assurance web frameworks yielded only 2 XSS bugs as of 4 September 2026.",
 "whyItMatters": "It shows a concrete design for suppressing AI-generated false positives. Google also reports that apps built on its secure-by-design frameworks yielded very few bugs to the agent, though that comparison is an uncontrolled self-report.",
 "actors": [
  "google"
 ],
 "topics": [
  "vulnerability-discovery",
  "autonomous-defense"
 ],
 "atlas": [
  "tools"
 ],
 "artifacts": [
  "pagebreak",
  "gemini"
 ],
 "sources": [
  {
   "url": "https://blog.google/security/agentic-hacks-real-proofs-inside-googles-pagebreak-project/",
   "publisher": "Google",
   "title": "Agentic Hacks, Real Proofs: Inside Google's PageBreak Project",
   "date": "2026-09-24",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "PageBreak began as a pilot in November 2025 and became a full project in January 2026; most usage relies on Gemini 3.1 Pro or Gemini 3.5 Flash.",
   "locator": "Section 'PageBreak'"
  },
  {
   "fact": "It uncovered over 500 XSS vulnerabilities across Google first-party web applications.",
   "locator": "Section 'PageBreak'"
  },
  {
   "fact": "As of September 4, 2026, only 2 XSS vulnerabilities were found across hundreds of apps built on Google's high-assurance web frameworks.",
   "locator": "Section 'PageBreak vs a High-Assurance Framework'"
  },
  {
   "fact": "Unverified candidate findings are kept as seeds for later scans and are not sent to product teams.",
   "locator": "Section 'Internal Feedback Loop'"
  }
 ],
 "significance": 3,
 "fideQuestions": [
  "FID-076"
 ],
 "methods": [
  "ai-vulnerability-discovery"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}