Google says its Gemini-based PageBreak agent has found more than 500 cross-site scripting flaws in the company’s web apps, testing suspected bugs against live copies to verify them. It found just two in apps built on newer “high-assurance” frameworks.
Cross-site scripting flaws can let attackers hijack logged-in sessions, steal data or impersonate users, Google says.
Google began PageBreak as a pilot in November 2025 and made it a full-fledged project in January 2026. Its next step is to connect the agent to CodeMender, an automated patch-writing agent, so engineers can review and approve proposed fixes.
