Cyber Security News

Google’s AI Hacker Finds 500+ XSS Flaws and Builds Working Exploit Chains

Google has revealed an internal AI security agent that found more than 500 verified cross-site scripting, or XSS, flaws across its own web applications.

The system, called PageBreak, searches for weaknesses that could let an attacker run unwanted code in a visitor’s browser, including on sensitive services. The announcement matters because AI scanners can generate large numbers of doubtful reports.

PageBreak instead tests each suspected weakness against a live environment, looking for proof that a real attack works before it is sent to engineers. This reduces noise while exposing hidden web weaknesses.

Analysts at tl;dr sec, referenced as Tdr SEC, highlighted PageBreak in their October 1 roundup. This was defensive testing, not malware or a confirmed intrusion. The Big Sleep vulnerability discovery project instead focused on a database flaw.

Google said in a public report, reviewed by Cyber Security News (CSN), that PageBreak began as a pilot in November 2025 and became a full project in January 2026. It primarily uses Gemini models within a proof-driven workflow.

Google’s AI Hacker Finds 500+ XSS Flaws

PageBreak examines code and traffic signals to identify possible weaknesses. It then hands that theory to a purpose-built validator rather than treating the AI output as a final security finding.

For XSS, the validator injects JavaScript, opens the target through a browser-like test system, and checks whether the code actually executes.

Rather than simply flagging risky-looking code, the scanner demonstrates the effect. Google attributes its near-zero false-positive rate to this verification. The same validation method can test SQL injection, path traversal, remote code execution, and server-side request forgery.

In a report on AI-powered Chrome bug fixes, automated systems were shown helping teams find, reproduce, triage, and patch browser bugs. PageBreak adds a key safeguard: it verifies the exploit path before escalating the issue.

The results also tested secure design. As of September 4, 2026, PageBreak found only two XSS issues among hundreds of applications built with its high-assurance web frameworks.

Both were limited to internal applications or debug endpoints with hardening gaps, showing why consistent framework controls can prevent whole classes of bugs.

Exploit Chains Expose Risks

The most notable findings were not simple input errors. In one case, PageBreak found a cache-poisoning issue affecting a JavaScript file server.

An unchecked URL path segment was inserted into returned code but excluded from the cache key, allowing a malicious response to be stored and later delivered to other visitors in the same geographic area.

Google found no evidence that attackers used that cache flaw. Still, it could have led to XSS on sensitive Google domains and external websites that loaded the affected JavaScript.

It reflects risks in CDN cache poisoning attacks, where shared responses can turn an input weakness into browser-side code execution.

A second chain affected the admin console. PageBreak found that an unverified redirect value could reach window.location, but a cryptographic signature initially blocked direct abuse.

The agent discovered a separate authorization endpoint that produced a valid signature for a malicious JavaScript URI, turning a protected endpoint into a working XSS path.

The third case involved the Tag Assistant Extension. Weak checks on external connections, recovery of a one-time nonce, and unsafe message forwarding allowed attacker-controlled script content to reach a page under debugging.

Support for data URLs then enabled arbitrary JavaScript execution, creating a universal XSS condition. Google retains unverified findings for future scans and validator improvements rather than sending them to product teams.

It also acknowledges that incomplete validators can miss genuine weaknesses. Its reported results support combining automated testing with secure frameworks, while engineers still review proposed fixes before changes reach users.

Google is working with automated patching initiatives to address the volume of confirmed reports. The intended outcome is to reduce product teams’ work to validating proposed fixes, rather than repeatedly investigating whether convincing AI-generated reports describe real security problems.

The source contains affected domains and test artifacts, not confirmed malicious infrastructure. These appear below for reference and should not be treated as a blocklist.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Affected domainapis.google.comJavaScript-serving domain affected by cache poisoning; not malicious infrastructure.
Affected domainadmin.google.comAdministrative console affected by the chained XSS finding.
Domaingoogle.comParent domain referenced in the extension connection scenario.
Domain pattern*.google.comAllowed connection pattern discussed in the extension case.
Example path/js/hello/file.jsIllustrative request showing how the server extracted an unchecked path segment.
Example path segment/js/helloSegment extracted from the illustrative request.
Proof-of-concept path/js/"-alert(1)-"/api.jsTest request demonstrating JavaScript injection.
Proof-of-concept URLhttps://apis.google.com/js/"-alert(1)-"/api.jsURL shown in the transformed JavaScript example, not observed attacker infrastructure.
File namefile.jsIllustrative JavaScript file name used in the routing example.
File nameapi.jsJavaScript resource whose cache entry could be poisoned.
Endpoint path/a/autodns/registrarAdministrative endpoint accepting the unvalidated redirect value.
Endpoint path/a/autodns/authorizeAuthorization endpoint used to obtain a valid signature for the malicious input.
Proof-of-concept URIjavascript:alert(1)Demonstration payload for the administrative console XSS.
Proof-of-concept data URLdata:text/javascript,alert(1)Demonstration payload for arbitrary script execution in the extension case.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Meta and Microsoft are Actively Cutting Employee Use of Claude AI

Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…

14 minutes ago

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

1 hour ago

FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

1 hour ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

2 hours ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

2 hours ago

Top 10 Best SAST Tools in 2026 [Ranked & Scored]

The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…

3 hours ago