Before a suspected flaw reaches developers, software validators must demonstrate it in a running app, which Google says keeps false positives near zero.
Google's Product Security team has outlined how PageBreak searches its web applications for exploitable flaws. The internal agent mainly uses Gemini models and draws on the company's source code, traffic data and existing security scanners.
The validators are written without AI and test each type of vulnerability differently. For cross-site scripting (XSS), a validator inserts a script into a page and checks whether it runs when the page loads. An attacker could use such a flaw to read another user's data or take over a signed-in session.
Google says PageBreak has found more than 500 XSS vulnerabilities across its web apps, including on sensitive domains. The company credits the validation step with a near-zero false-positive rate, reducing the burden of investigating plausible but unproven AI-generated reports.
Google attributes much of PageBreak's reach to its infrastructure. Its unified code repository lets PageBreak follow execution paths across services, while traffic data connects web requests to source code. The company says an established scanner handles authentication for nearly every Google web app, giving PageBreak access even to internal sites that security engineers may struggle to scan.
Among hundreds of applications built on Google's high-assurance web frameworks, PageBreak had found only two XSS flaws as of September 4. Those were confined to internal applications or debug endpoints with incomplete hardening. Google presents these findings as evidence for building security into frameworks.
Google acknowledges that the validators cannot yet handle every vulnerability type or complex scenario and may therefore miss genuine bugs. Unconfirmed candidates stay within the security workflow, informing later scans and the development of new validators. They are not passed to product teams as verified findings.
Even verified reports arrive in volumes that strain product teams, Google says. PageBreak already works with automated patching projects, including CodeMender. Google plans closer integration so developers can review proposed fixes alongside the confirmed bugs.
Cover image: “Google Headquarters Google Logo” by Anthony Quintano, Wikimedia Commons, CC BY 2.0, resized, re-encoded.