Google’s AI Hacker Finds 500+ XSS Flaws and Builds Working Exploit Chains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Google has revealed an internal AI security agent that found more than 500 verified cross-site scripting, or XSS, flaws across its own web applications.

The system, called PageBreak, searches for weaknesses that could let an attacker run unwanted code in a visitor’s browser, including on sensitive services. The announcement matters because AI scanners can generate large numbers of doubtful reports.

PageBreak instead tests each suspected weakness against a live environment, looking for proof that a real attack works before it is sent to engineers. This reduces noise while exposing hidden web weaknesses.

Analysts at tl;dr sec, referenced as Tdr SEC, highlighted PageBreak in their October 1 roundup. This was defensive testing, not malware or a confirmed intrusion. The Big Sleep vulnerability discovery project instead focused on a database flaw.

Google said in a public report, reviewed by Cyber Security News (CSN), that PageBreak began as a pilot in November 2025 and became a full project in January 2026. It primarily uses Gemini models within a proof-driven workflow.

Google’s AI Hacker Finds 500+ XSS Flaws

PageBreak examines code and traffic signals to identify possible weaknesses. It then hands that theory to a purpose-built validator rather than treating the AI output as a final security finding.

For XSS, the validator injects JavaScript, opens the target through a browser-like test system, and checks whether the code actually executes.

Rather than simply flagging risky-looking code, the scanner demonstrates the effect. Google attributes its near-zero false-positive rate to this verification. The same validation method can test SQL injection, path traversal, remote code execution, and server-side request forgery.

In a report on AI-powered Chrome bug fixes, automated systems were shown helping teams find, reproduce, triage, and patch browser bugs. PageBreak adds a key safeguard: it verifies the exploit path before escalating the issue.

The results also tested secure design. As of September 4, 2026, PageBreak found only two XSS issues among hundreds of applications built with its high-assurance web frameworks.

Both were limited to internal applications or debug endpoints with hardening gaps, showing why consistent framework controls can prevent whole classes of bugs.

Exploit Chains Expose Risks

The most notable findings were not simple input errors. In one case, PageBreak found a cache-poisoning issue affecting a JavaScript file server.

An unchecked URL path segment was inserted into returned code but excluded from the cache key, allowing a malicious response to be stored and later delivered to other visitors in the same geographic area.

Google found no evidence that attackers used that cache flaw. Still, it could have led to XSS on sensitive Google domains and external websites that loaded the affected JavaScript.

It reflects risks in CDN cache poisoning attacks, where shared responses can turn an input weakness into browser-side code execution.

A second chain affected the admin console. PageBreak found that an unverified redirect value could reach window.location, but a cryptographic signature initially blocked direct abuse.

The agent discovered a separate authorization endpoint that produced a valid signature for a malicious JavaScript URI, turning a protected endpoint into a working XSS path.

The third case involved the Tag Assistant Extension. Weak checks on external connections, recovery of a one-time nonce, and unsafe message forwarding allowed attacker-controlled script content to reach a page under debugging.

Support for data URLs then enabled arbitrary JavaScript execution, creating a universal XSS condition. Google retains unverified findings for future scans and validator improvements rather than sending them to product teams.

It also acknowledges that incomplete validators can miss genuine weaknesses. Its reported results support combining automated testing with secure frameworks, while engineers still review proposed fixes before changes reach users.

Google is working with automated patching initiatives to address the volume of confirmed reports. The intended outcome is to reduce product teams’ work to validating proposed fixes, rather than repeatedly investigating whether convincing AI-generated reports describe real security problems.

The source contains affected domains and test artifacts, not confirmed malicious infrastructure. These appear below for reference and should not be treated as a blocklist.

Indicators of compromise (IoCs):-

Type Indicator Description
Affected domain apis.google.com JavaScript-serving domain affected by cache poisoning; not malicious infrastructure.
Affected domain admin.google.com Administrative console affected by the chained XSS finding.
Domain google.com Parent domain referenced in the extension connection scenario.
Domain pattern *.google.com Allowed connection pattern discussed in the extension case.
Example path /js/hello/file.js Illustrative request showing how the server extracted an unchecked path segment.
Example path segment /js/hello Segment extracted from the illustrative request.
Proof-of-concept path /js/"-alert(1)-"/api.js Test request demonstrating JavaScript injection.
Proof-of-concept URL https://apis.google.com/js/"-alert(1)-"/api.js URL shown in the transformed JavaScript example, not observed attacker infrastructure.
File name file.js Illustrative JavaScript file name used in the routing example.
File name api.js JavaScript resource whose cache entry could be poisoned.
Endpoint path /a/autodns/registrar Administrative endpoint accepting the unvalidated redirect value.
Endpoint path /a/autodns/authorize Authorization endpoint used to obtain a valid signature for the malicious input.
Proof-of-concept URI javascript:alert(1) Demonstration payload for the administrative console XSS.
Proof-of-concept data URL data:text/javascript,alert(1) Demonstration payload for arbitrary script execution in the extension case.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Google’s AI Hacker Finds 500+ XSS Flaws and Builds Working Exploit Chains appeared first on Cyber Security News.