
Here is the uncomfortable part of security work in 2026. Large language models are genuinely good at reading code and spotting things that look wrong. They are also, in the words of Google's own security team, very good at producing what one researcher calls "AI slop" — a flood of confident, unverified, often flatly wrong vulnerability reports. Security teams did not ask for more hypotheses. They asked for fewer. So Google built something that does not believe its own scanner.
The tool is called PageBreak, an internal agent built by Google's Product Security team to test the company's first-party web applications. Michał Bentkowski, an information security engineer at Google, wrote up how it works, and on September 29 the Google VRP — the Google Bug Hunters account — announced it publicly. It started as a pilot in November 2025 and became a full project in January 2026. It runs mostly on Gemini, including Gemini 3.1 Pro and 3.5 Flash, though the architecture is deliberately model-flexible.
The design decision that matters came early, and it is worth sitting with. Rather than asking a model to hypothesize a bug and then trusting it, PageBreak insists on proof. When the agent thinks it has found something, it hands the hypothesis to a validator — and those validators are not written by an AI. They are ordinary, hand-written programs whose only job is to actually attack the thing and see what happens. For a suspected cross-site scripting flaw, the validator injects a JavaScript payload, loads the URL through a real rendering harness, and watches to see whether the injected script actually executes. For suspected SQL injection it manipulates the query and checks the output, or the timing. For path traversal it drops a file somewhere world-readable and then tries to read it back. For remote code execution it tries several proofs at once: inducing a sleep delay, writing into a world-writable directory, or triggering an outbound DNS or HTTP request. For SSRF it watches for the application's request landing on an internal service.
Run across Google's web estate, that approach turned up more than 500 cross-site scripting vulnerabilities, including on sensitive domains. A near-zero false positive rate was not a nice-to-have metric; it was the entire point. The alternative was handing product teams a queue of unverifiable noise and making their jobs harder, which is the opposite of what an agentic scanner is supposed to do.
PageBreak is not pretending to be complete, and that honesty is the most interesting part of the post. Its validators do not cover every vulnerability class or every messy edge case, which means the system risks false negatives — real bugs it never confirms. So Google runs the agents with identical seeds across many iterations, because models wander down unproductive paths and repetition raises the odds of stumbling onto the right exploit chain. It also collects non-deterministic findings, and uses them for three things: seeding deeper inspection on later runs, showing engineers where the validators are weak, and telling the team which capabilities or environment access the agent lacks so it could verify a report. Notably, those unverified findings are never sent to product teams.
Then came the test result that is arguably the more interesting story. Google previously published a blueprint for a high-assurance web framework designed to eliminate exploitable web vulnerabilities by default. When PageBreak was pointed at applications built on those frameworks, they held up. As of September 4, 2026, the scanner found exactly two XSS vulnerabilities across hundreds of such applications, and both were confined to internal apps or debug endpoints with hardening gaps. A well-built safe-by-design framework is a hard target for an agent that can actually verify exploits.
Part of that is architecture and part is unfair advantage. Google keeps billions of lines in a monorepo, so an agent can follow a full execution path end to end without ever leaving the repository — including the service configurations, which is how a cache poisoning XSS slipped through in a companion write-up. PageBreak also pulls security signals from live HTTP traffic to map URL paths back to specific source lines, and it repurposes a Google scanning suite, including a scanner that can authenticate to nearly every Google web application. That last one matters: it means the agent can assess internal sites that most human security engineers cannot reach, let alone scan on a schedule.
Google is now wiring PageBreak into other agentic efforts, including CodeMender, which generates automated fixes. The stated goal is that product teams end up doing nothing but validating a proposed patch. That is the whole trajectory: not a scanner that files tickets, but a system that finds a flaw, proves it, and proposes the repair before anyone gets paged.
Not everyone is convinced. Replies under the announcement include a security researcher noting that individual researchers still cannot get access to the kind of specialized cyber model PageBreak runs on, and a jab that Google had this capability before, pointing to earlier work out of Daybreak and Glasswing. Both are fair. Google is not releasing PageBreak, and the model access gap between a Google-internal agent and an outside researcher is exactly the sort of thing that makes a community sour about a demo. The Bug Hunters account already draws plenty of complaints about duplicate verdicts and silent fixes.
But those complaints land on a different project. The Vulnerability Reward Program is about triage and adjudication for human submissions. PageBreak is about making sure that when a machine claims an XSS exists, someone already tried to execute it first. That is a narrower claim than "AI finds all your bugs," and it is a much more believable one. Five hundred verified cross-site scripting bugs is a number you can check. Zero invented ones is a number you can audit. The rest of the security AI discourse could use the same discipline: prove it, then claim it.
Google has published a companion post on the Google Bug Hunters blog with the actual vulnerabilities PageBreak found, including the cache poisoning flaw and a case where the agent bypassed cryptographic protections on its own.
Comments